57,566 vulnerabilities published in 2026
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and Pe
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled c
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF proc
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahd
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE de
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unus
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote at
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated r
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload
TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unesca
TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect follo
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() f
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulne
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to cre
Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenti
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoof
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu
A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-ST
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 docum
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass m
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be ret
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Files
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injectio
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 thro
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The v
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` i
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromB
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBacku
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encry
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe pr
A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6400 v7. An unauthent
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started