57,566 vulnerabilities published in 2026
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attac
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using p
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any t
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access co
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in th
The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo
C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar
Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with cust
Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or mo
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co.
Crafted delegations or IP fragments can poison cached delegations in Recursor.
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_h
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to fil
Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/
Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar
Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may all
Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, c
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a netwo
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose informatio
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what
Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents
Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo
Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may al
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrap
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started