57,566 vulnerabilities published in 2026
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize
A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se
Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo
MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API.
MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust
Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve
veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc
ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.
A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh
The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based b
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In
Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper wh
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma
Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Ele
PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer a
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previous
Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAu
Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attack
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client ac
MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool p
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started