57,566 vulnerabilities published in 2026
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av
Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method return
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms duri
The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow
PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A
Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-au
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file
@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths
Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten
A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an
@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instance
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_e
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to syst
OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route su
xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP ca
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio
xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentic
The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 hav
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause
Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrati
A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare
Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges o
Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may t
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formu
Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jell
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes
A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be
In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-b
Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expr
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started