57,566 vulnerabilities published in 2026
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forg
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also
In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also af
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticat
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote atta
FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-c
eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security r
CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functio
CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endp
CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. Th
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile
Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r
Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a
Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulne
Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to
Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese
Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in
A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pc
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication
Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu
Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint byp
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A
A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started