57,566 vulnerabilities published in 2026
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Ap
Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using anoth
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication
Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypa
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software all
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software al
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili
CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne
CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists
CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_se
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE)
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP
The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.
Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-contr
Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a
OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptRe
phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the L
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set
Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers
DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelet
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did
When adding a key to a remote agent constraint extensions such as [email protected] were not serializ
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enf
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started