57,566 vulnerabilities published in 2026
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stor
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de
The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t
Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys wit
MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not en
Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filt
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL
The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa
Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.
SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right
The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica
varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with role
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any b
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer
Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user ac
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enab
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.acce
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started