57,566 vulnerabilities published in 2026
A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Window
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 un
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility a
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/ac
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape ex
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 -
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vuln
HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read fro
Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id acce
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortc
Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js
Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download
Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments a
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via une
Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hoo
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App:
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly co
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a mali
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter proces
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically cra
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically craft
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/sc
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnera
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether th
The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoi
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read ac
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HT
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INIT
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct pat
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - A
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim co
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started