57,566 vulnerabilities published in 2026
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Co
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL
A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Pro
Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a criti
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 1
Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database
Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a S
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak Keyc
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d
Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of boun
Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl
A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session ide
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `Clien
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request ma
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request ma
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2
The administrative credentials can be extracted through application API responses, mobile application reverse engineerin
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vuln
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage
Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tick
A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-sc
pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer o
On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all author
Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via
In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, S
A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== ins
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator w
An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The i
An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding
Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD
Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious F
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manag
The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Sales
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started