57,566 vulnerabilities published in 2026
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing local privilege escalation to the Reporter service context.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent no
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Reco
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Pyt
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validat
Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning end
pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnera
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organiz
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt inject
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access co
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 co
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d
In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An au
In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to cat
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the Si
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-C
In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_valid_fib_dump_req() o
In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eepro
In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on inser
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV
In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: preallocate inexact bins before xfrm_
Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau
Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D re
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows
Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses Po
PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.
Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers
NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a d
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started