57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Expl
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php co
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with b
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider
LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side
Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoi
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connecto
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-S
Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations
Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint acce
prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status pol
PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API fu
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request
OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-contro
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user w
Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index dat
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_c
OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to re
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the
Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect avai
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f
xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Auth
Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/edit
NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A succ
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.
Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cros
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensi
Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started