57,566 vulnerabilities published in 2026
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template
Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu
An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer
A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI
A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with
A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started