57,566 vulnerabilities published in 2026
Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Fo
Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was
Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I
Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag
Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP
Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def
Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET
Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and
A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules.
A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the
Various sensitive information such as passwords and charging card UIDs are written to log files.
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose
The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co
Stored Cross-Site Scripting (XSS) vulnerability in the RD Station Conversas chat. The vulnerability resides in the ‘name
Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu
Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validat
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This v
ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attac
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was
HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can
Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory o
Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (
A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible deb
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The m
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowed
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started