57,566 vulnerabilities published in 2026
Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend
SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from th
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the iden
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI be
SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new G
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endp
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Z
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows at
Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.
Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin func
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and u
pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnera
FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insuffi
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Ka
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the re
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction
Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to ve
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.2
ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL
ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL
Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2
Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input
Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input
Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-con
grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC too
Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RS
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerabil
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript t
Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/c
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read API
Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. The
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a
A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have cre
Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Boar
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started