57,566 vulnerabilities published in 2026
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an O
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF
Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf end
The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-p
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaust
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could b
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length para
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpe
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of en
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit re
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attac
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially craf
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from samp
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the Enc
Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerabilit
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitr
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulner
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forw
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerc
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable val
Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files ou
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started