57,566 vulnerabilities published in 2026
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, m
In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, the
The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd
The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis
Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-tea
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fiel
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, aut
Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Re
When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSR
WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository con
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec t
A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security A
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) So
OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in wh
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass v
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetche
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0
Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Manageme
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, th
arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val
Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc
An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut
Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to cra
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in v
An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptograph
A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an aut
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant V
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox e
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.1
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started