57,566 vulnerabilities published in 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to sto
The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, th
Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exac
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cro
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate cer
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate reque
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Genera
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2,
broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are c
Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Ver
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints i
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB
Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the r
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML.
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 a
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially
A lack of proper input validation in the HTTP processing path in TP-Link Archer BE230 v1.2 (web modules) may allow a cra
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the admi
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu
Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_u
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the componen
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the form
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtp
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive o
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component
Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne
A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain lim
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_
A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int
In Mimecast Incydr before 2.6.0, arbitrary file access can occur.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started