57,566 vulnerabilities published in 2026
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili
Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Re
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe
Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including,
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attacker
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions u
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pi
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_c
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Si
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started