57,566 vulnerabilities published in 2026
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address
A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC
CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb
Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket tr
Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize
Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per
Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for
Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a loca
The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — n
Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an at
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Obje
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code executio
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint pr
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicem
SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L
@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrenc
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a le
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent
### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the pe
@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,
In the Linux kernel, the following vulnerability has been resolved: block: Avoid mounting the bdev pseudo-filesystem in
In the Linux kernel, the following vulnerability has been resolved: f2fs: read COW data with the original inode during
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix missing read bio submission on large foli
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: usb: fix memory leaks on USB write fai
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix warning when unbinding If there
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started