57,566 vulnerabilities published in 2026
Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary c
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector pas
WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t
Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Al
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint tha
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_strin
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc
maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the au
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when pro
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile f
NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds re
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vo
HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote cha
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04
In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure Wh
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authen
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-ht
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes
XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipula
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s
OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that al
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decod
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement
Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac
In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_roundoff values If the
In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ reco
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client
i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to ext
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handle
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started