57,566 vulnerabilities published in 2026
PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implemen
EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to rep
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacke
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I
An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "str
Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unb
Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via
Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en
WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen
Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex
Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens
Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali
STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l
Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pp
Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and othe
Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared
Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed
Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, t
gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference S
Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows auth
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / da
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Con
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_re
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi)
OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected bou
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::c
HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeStri
Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{
Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticat
Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certifica
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove
Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a
Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev
A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly pri
A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside t
A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly cre
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload
Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure P
Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started