57,566 vulnerabilities published in 2026
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rend
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Ev
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-d
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level atta
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacke
Ebyte device web management interface does not consistently enforce authentication before granting access to administra
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us
An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after s
In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[]
In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsu
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size fo
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_red
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to
In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden
In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_
In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced co
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances an
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating un
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentic
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated at
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcemen
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthentic
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lac
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versio
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5.
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthe
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulne
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A s
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started