57,566 vulnerabilities published in 2026
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization
The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw
SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an ou
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker ca
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote att
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ th
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthe
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP mes
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_s
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F
nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (
microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to sto
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started