57,566 vulnerabilities published in 2026
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with th
liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verif
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header conta
u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5
CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptogr
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensiti
Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calend
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to e
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary c
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote
AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717
uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an auth
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised acce
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni
Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun
URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API requ
A validation vulnerability has been identified in certain web features related to file management or upload in several p
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code i
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cros
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Requ
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st
FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticate
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `Client
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product fi
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started