57,566 vulnerabilities published in 2026
A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unb
Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2
Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring
OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbea
Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.updat
Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote
A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in sou
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sani
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such a
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A s
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A spec
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effectiv
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this
ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a r
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces
FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a
wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git pus
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforc
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP
Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection throu
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote auth
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command
Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web She
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP 
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias
Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches on
OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm modu
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E
Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started