57,566 vulnerabilities published in 2026
OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea
@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching m
A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to
ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_contr
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails
Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passe
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc
Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validatio
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Valid
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi
Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite
Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attacker
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacke
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started