57,566 vulnerabilities published in 2026
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo
Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13
openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any g
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a use
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the r
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. Th
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, sever
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use
PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the l
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the A
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust j
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un
Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma
The system stores the username and password from the login form after submitting the request. This could allow an attack
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject
Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl
The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard
Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab
A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affe
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started