57,566 vulnerabilities published in 2026
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrat
Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote att
A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via ma
A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user te
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&ac
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Man
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allow
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manag
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-update
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated a
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe impor
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on
n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1
CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, t
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spri
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Inte
Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Sp
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacke
Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-sup
Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response split
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu ent
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woylie doggo allow
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue c
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulne
Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 al
In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a D
A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allo
A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd
A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allo
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to s
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th
cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes
cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security fe
WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN pac
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to ex
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker t
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started