57,566 vulnerabilities published in 2026
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to exe
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher
A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be per
A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on th
A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established wi
A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration end
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the hap
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the
Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.
Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion with
In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_inv
In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret
In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_s
In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response
In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode T
In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by referen
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buf
In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_est
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on net
Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain uninte
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassC
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payloa
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types)
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classe
Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This is
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-b
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function s
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEa
A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allow
ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorage
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the fi
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/S
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP s
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCf
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started