57,566 vulnerabilities published in 2026
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt
Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to mani
WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key r
Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test
Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows
Gitea does not properly validate project ownership in organization project operations. A user with project write access
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data
AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and pr
Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protec
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue a
Squidex is an open source headless content management system and content management hub. Versions of the application up
Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Vers
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio
In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when loggin
A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadm
MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication,
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT)
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a
SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not valid
html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries thro
Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory change
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critic
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's
macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workf
C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to rea
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts serv
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derive
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authori
newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not inco
authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using de
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started