57,566 vulnerabilities published in 2026
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-pri
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbit
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_conte
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handlin
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolle
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (includin
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrict
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During th
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions duri
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated a
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an a
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an auth
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or updat
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restor
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated user
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access b
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacke
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper ne
In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /gofor
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/fo
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed clust
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes Suppr
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticate
ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransac
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated princ
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to jo
Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url w
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/Sys
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started