57,566 vulnerabilities published in 2026
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless
Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integrati
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauth
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vu
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped au
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, appl
Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically register
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versio
LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can exec
Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3
The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL
A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps ou
A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly wi
The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no jo
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously c
Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed c
The vulnerability allows the unauthorised generation of physical access QR codes due to the use of hard-coded credential
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged n
An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Servi
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause
In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: fix NULL pointer dereference in ar_
In the Linux kernel, the following vulnerability has been resolved: l2tp: fix tunnel and session refcount leak on seq_f
In the Linux kernel, the following vulnerability has been resolved: regmap: sdw-mbq: don't call an unset readable_reg c
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix TOCTOU NULL deref on a->got
In the Linux kernel, the following vulnerability has been resolved: rseq: Prevent hard lockup on granted time slice ext
In the Linux kernel, the following vulnerability has been resolved: scsi: core: pair EH runtime PM get and put shost->
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python pr
In the Linux kernel, the following vulnerability has been resolved: optee: ffa: Add NULL check in optee_ffa_lend_protme
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Refresh copier IPC payloa
In the Linux kernel, the following vulnerability has been resolved: xfs: don't swallow dquot recovery verification erro
In the Linux kernel, the following vulnerability has been resolved: xfs: fix another iunlink infinite loop bug in onlin
In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a null sc->sa.agi_bp
In the Linux kernel, the following vulnerability has been resolved: xfs: fix ilock leak on error in xfs_dq_get_next_id
In the Linux kernel, the following vulnerability has been resolved: xfs: don't double-lock when deleting a self-referen
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: disallow multiple FENCE chunks in one s
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference in am
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Pad trailing CCA or EP11 message with
In the Linux kernel, the following vulnerability has been resolved: gpio: ml-ioh: use raw_spinlock_t for the register l
In the Linux kernel, the following vulnerability has been resolved: gpio: sloppy-logic-analyzer: fix use-after-free via
In the Linux kernel, the following vulnerability has been resolved: gve: fix NULL dereference due to missing ptp adjfin
In the Linux kernel, the following vulnerability has been resolved: Input: hynitron_cstxxx - validate touch count and f
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - propagate F54 worker errors
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: papr-phy-attest - validate cmd.len
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - validate input packet lengths ifor
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: skip zero-sized firmware sections pan
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the S
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary s
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started