57,566 vulnerabilities published in 2026
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale
Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect avail
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availabi
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge
Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role Sys
A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getPar
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access
Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user
A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporte
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of se
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values be
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g
The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started