57,566 vulnerabilities published in 2026
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l
Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)
A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.
Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly acces
Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrec
This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho
Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne
A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin
An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer S
Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So
The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform
An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u
An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privi
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module)
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism gener
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists i
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header fo
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the
NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection v
The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to direct
Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls ba
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started