57,566 vulnerabilities published in 2026
An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a
Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of
An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte
An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE
An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte
Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cau
An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to
Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers
A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Deni
An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a
An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted
A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (D
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Se
Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fai
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functiona
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/captu
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticate
In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading t
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue acr
Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authori
Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint a
Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: *
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That doe
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <=
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrat
Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote att
A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via ma
A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user te
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&ac
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Man
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allow
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manag
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-update
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started