57,566 vulnerabilities published in 2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server version
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a
An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accou
MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. W
A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the
MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegatio
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to
An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view
A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint pre
MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisa
MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inse
An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs du
A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manip
An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions t
The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi
The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between t
The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptogra
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability i
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the docume
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type valid
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not pr
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the Sa
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code wh
Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users
Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restrictio
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a
LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars
LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c
LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute work
Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might all
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to acc
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grp
Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor
A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earli
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started