57,566 vulnerabilities published in 2026
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou
OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media atta
OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows privat
OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut
A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated,
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san
FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa
In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to gl
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.page
WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsyn
Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API end
Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se
python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.p
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, throu
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Ser
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, d
Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) valida
Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automa
Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/inte
Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/dataso
Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sd
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_pu
OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey ro
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypas
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creat
MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.Ge
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started