57,566 vulnerabilities published in 2026
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a ne
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe
In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adju
In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segment
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbi
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the functio
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the fi
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent
An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system dat
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files int
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, an
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized co
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting p
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The is
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blog
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects Ne
Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressi
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav
Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell end
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection
Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service c
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started