57,566 vulnerabilities published in 2026
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag with
Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content t
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts in
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent`
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAge
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent
Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection
Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the priv
Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensit
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files wi
Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persiste
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privil
Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary co
Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive inf
Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure Tence
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files
Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files wi
Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to ac
Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute a
Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device i
Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bo
R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co
R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML an
R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password
R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command exe
mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT
SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject
Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enfo
Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind
Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust ser
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its t
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir
grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5
ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the
ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scri
OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3
Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started