57,566 vulnerabilities published in 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artif
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet
The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and es
Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co
CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in
The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c
An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability,
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported version
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vau
CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions
Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Requ
Server-Side Request Forgery (SSRF) vulnerability in wbolt.com IMGspider imgspider allows Server Side Request Forgery.Thi
Missing Authorization vulnerability in Roxnor GetGenie getgenie allows Exploiting Incorrectly Configured Access Control
The WP-ClanWars plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, a
Tanium addressed an uncontrolled resource consumption vulnerability in Discover.
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-leve
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di
Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM
Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with ade
An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by res
The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t
The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para
The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedI
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load
In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started