57,566 vulnerabilities published in 2026
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by th
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in Un
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enabl
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDas
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Usi
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management t
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result i
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started