57,566 vulnerabilities published in 2026
OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily
Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection t
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t
A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket pr
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-cont
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a
A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilt
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme
ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnera
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attac
An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent
An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent
A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/
Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent net
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, a
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the fil
Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes execu
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the
Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h
Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mo
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t
An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any a
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-boun
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer ove
Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration
IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started