57,566 vulnerabilities published in 2026
Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un
Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding:
Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers w
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl
Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s
Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound
Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFor
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options end
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in AS
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09
Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are e
Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdm
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on
In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regi
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filte
In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received
In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon
This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argu
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started