57,566 vulnerabilities published in 2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be h
VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malic
Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functio
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au
IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru
IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recur
A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Acce
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect a
OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof
IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerabili
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to reg
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulne
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich S
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Briano Li
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste
The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as c
Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket
wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy mat
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications c
phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, an
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started