57,566 vulnerabilities published in 2026
SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca
SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-
In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could en
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the applicat
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6,
CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the u
Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user sp
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex
Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale paramete
Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write
Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th
Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo
NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access co
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Split
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allow
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2
NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.
NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php
NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php
NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.ph
Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has
An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. Thi
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested dire
Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported pl
Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms
Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platfor
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to l
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists i
ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name,
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started