57,566 vulnerabilities published in 2026
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use
U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFI
Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco
PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_ur
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Str
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow co
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface c
Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site script
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima
9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by re
EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory
Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to
Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c
MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauth
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bo
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is c
PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/prai
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and
A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove t
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that a
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif
Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is in
QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid sessio
In the Linux kernel, the following vulnerability has been resolved: mptcp: close TOCTOU race while computing rcv_wnd T
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on in
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started