57,566 vulnerabilities published in 2026
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to c
IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a de
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the
Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipula
Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths w
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p
An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr
A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre
Transient DOS when processing a received frame with an excessively large authentication information element.
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage me
A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the coll
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQue
Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Serio
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Co
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem
Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Conf
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Hogg The Eve
Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Acce
GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usern
A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The
JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet
pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative fun
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clo
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denia
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitr
If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such m
The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i
The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers
A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started