57,566 vulnerabilities published in 2026
Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in t
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamVie
Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi
Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CS
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an autho
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket
An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
The web management interface of the device renders the passwords in a plaintext input field. The current password is di
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser
OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that tru
Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/p
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivat
Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentic
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR)
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing ta
CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk conta
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (m
monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f
GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started