57,566 vulnerabilities published in 2026
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76
OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses
Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s
curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond
Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO
Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availabil
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a
A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation
A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p
A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation.
Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta
Concurrency and locking defects in GSS-TSIG
Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYP
Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_V
Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIF
Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta
Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows att
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a pa
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incor
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the
Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai
Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Acti
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started