57,566 vulnerabilities published in 2026
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbit
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerabil
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authentic
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Bud
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content
Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1
Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu
2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE)
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23
Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the
Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog al
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possi
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injectio
An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap
### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen
The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hard
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a
Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Rem
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does
AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918)
A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a fo
Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted,
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Fact
WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started