57,566 vulnerabilities published in 2026
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e
In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain
Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher
Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex
Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first
Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont
Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat
Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, w
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated us
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Gi
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operati
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When
n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenti
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started