57,566 vulnerabilities published in 2026
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthentic
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasse
## Summary
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful expl
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a
toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands,
WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec
Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh
Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T
In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVE
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker co
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature
ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed du
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a cli
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confir
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p
rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicio
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by trigge
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metada
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started