57,566 vulnerabilities published in 2026
Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthen
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impe
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the va
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key excha
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem
In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed p
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r
In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_p
GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scannin
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authen
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 1
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such a
Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe
phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when prope
mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod
form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys
Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information
E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate datab
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb
MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execut
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started