57,566 vulnerabilities published in 2026
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagist
An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211
Cryptographic issue may occur while encrypting license data.
devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows loca
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticat
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al
CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attacke
Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users
Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to pot
Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local
Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute
ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. A
VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrar
Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local a
Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execu
Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows
Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows
CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with
Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca
Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to
Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab
Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnera
Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C
YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allo
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @f
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalati
IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Inte
A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol
dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to over
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for
docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to ex
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started