57,566 vulnerabilities published in 2026
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. Th
Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdo
Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Conten
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without outp
Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or s
A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service
A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file co
A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown functi
A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor
A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all
A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of t
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Op
A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown funct
A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown functio
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of
A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability
A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects
A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function o
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthen
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Convert macros to functions to avo
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
A vulnerability has been found in bastillion-io Bastillion up to 4.0.1. This vulnerability affects unknown code of the f
A vulnerability was found in bastillion-io Bastillion up to 4.0.1. This issue affects some unknown processing of the fil
A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/pub
A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown funct
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005
EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol.
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sani
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign
In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two
A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode o
A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic
A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repositor
Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-S
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function
A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /b
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started