57,566 vulnerabilities published in 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interf
Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an
When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If
Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerabi
Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privile
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Pri
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authenticati
Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file searc
OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic
Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allow
Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to by
A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authentic
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suit
CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attack
opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i
Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packet
filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographi
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file mo
An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special
An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax
HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and fa
Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing add
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not includin
Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inj
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/
SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create
Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute J
Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaS
Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery
The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 20
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows
An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve
LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveC
Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU Kr
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the i
The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This
Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin
SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input valid
A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid
The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage
Improper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtu
Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an
Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated use
Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Script
Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticate
A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started