2026
57,566 vulnerabilities published in 2026
A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user ac
An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attacke
AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may all
A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management
A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud V
Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS)
In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Fix false-positive kmsan report in fpu_vs
In the Linux kernel, the following vulnerability has been resolved: iavf: Implement settime64 with -EOPNOTSUPP ptp_clo
In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm Th
In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I
In the Linux kernel, the following vulnerability has been resolved: block: Use RCU in blk_mq_[un]quiesce_tagset() inste
In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release
In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LE
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Fix potential memory leaks in rtl818
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential out-of-bounds read in iomm
In the Linux kernel, the following vulnerability has been resolved: net: netpoll: initialize work queue before error ch
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Correctly handle return of sg_ne
In the Linux kernel, the following vulnerability has been resolved: mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_st
In the Linux kernel, the following vulnerability has been resolved: irqchip/mchp-eic: Fix error code in mchp_eic_domain
An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads
Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dn
AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticate
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. Th
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware.
Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she
The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV
The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows cont
An attacker with access to the system's internal network can cause a denial of service on the system by making two concu
An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured
The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate pri
The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files c
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is n
An attacker with a network connection could detect credentials in clear text.
As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could ob
OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client
Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec
Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec
Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users
An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via s
A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is
A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall co
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the p
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the t
The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the m
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the u
AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerabilit
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started