57,566 vulnerabilities published in 2026
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injecti
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module.
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path)
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds t
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lock
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started