57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write()
In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_b
In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in sn
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check for tg ops in dce110_set_avm
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vuln
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Build
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authentic
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth rang
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An atta
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 al
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sens
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 all
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of
RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint p
RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated rem
RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked
Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlle
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim
RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The
RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents ar
RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Locati
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an a
Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackdu
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en
RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocu
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net
The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5
Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injectio
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative acces
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls M
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, B
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenti
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug
Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositor
Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their res
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started