57,566 vulnerabilities published in 2026
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memca
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configur
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forg
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exis
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validat
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiM
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from A
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu
The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function
An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.
Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un
Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0
Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2
Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exist
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parame
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments
SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization d
OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin va
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attacker
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enfor
Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerabi
Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allow
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glance
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZ
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker t
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started