57,566 vulnerabilities published in 2026
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access
manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintex
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an
Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload maliciou
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasic
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic
Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P
Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from
Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary co
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent ex
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalati
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unaut
OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The pr
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 al
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated atta
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated at
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the usernam
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded passw
GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u
The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .N
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS
A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 softwa
A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated us
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The pr
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started