57,566 vulnerabilities published in 2026
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Beca
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauth
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open X
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbit
WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate
WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers
A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of th
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apac
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue a
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middlewa
In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar f
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when Raise
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attack
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to
QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or tr
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
Improper neutralization of special elements used in an expression language statement ('expression language injection') v
Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclu
SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This iss
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php en
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started