57,566 vulnerabilities published in 2026
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks r
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXE
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backl
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vul
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that a
In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro
In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on g
In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main t
In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong lo
In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wr
In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrup
In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircui
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_ur
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function st
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of th
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started