57,566 vulnerabilities published in 2026
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote atta
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated wi
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registere
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san
Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15)
Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19)
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability
SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary cod
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abu
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu
Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started