57,566 vulnerabilities published in 2026
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, admin
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the L
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multi
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a mi
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Sto
SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionalit
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an atta
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thund
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes id
An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vu
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database ut
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, data
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Servi
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH tra
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o
The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As
e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p
FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The
FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mut
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublic
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on t
The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling in rxgk_extract_token()
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunn
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started