57,566 vulnerabilities published in 2026
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remot
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remot
A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbi
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default C
The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin
Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in u
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app con
PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execut
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re
The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed thr
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization che
A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the
WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files throug
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `wei
Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress
The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables
An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject ar
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components o
OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitr
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions b
MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized user
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force
An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corru
A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and includin
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution
A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of th
A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor
Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension rest
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authentica
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary O
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9
In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adja
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started