57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and
bestzip builds the argument list for the system zip utility without separating options from operands. The destination ar
The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with repl
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext w
In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_atk0110) Check package count before ac
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - only expose sysfs attributes on co
In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Add slave_destroy interface for v3
In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Fix slave registration race and error han
In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: write the feature value before
In the Linux kernel, the following vulnerability has been resolved: io_uring: preserve task restrictions across exec P
In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic
Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL
EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse
A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerab
Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cl
Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pr
Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploita
eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the se
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -ski
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi
OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that al
OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit exte
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behavi
SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenti
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW
Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW
GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg
A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuratio
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen
The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL querie
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or rej
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-prov
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp
Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started