57,566 vulnerabilities published in 2026
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe
The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input.
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An
The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (
Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power
Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerabil
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces
mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Ma
NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the
SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'mo
Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session P
Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit
Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthentic
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform
Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary Fi
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.
A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitiza
A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search ind
Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website wi
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p
A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzin
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl
vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the re
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable fi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started