57,566 vulnerabilities published in 2026
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission
The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir
TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in
Backend users with write access to the form_definition database table were able to directly create, update, or delete fo
Backend users with file download permissions were able to download files from the fallback storage of the file abstracti
When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a loc
The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with
Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the
Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attri
Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who c
Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts t
Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg
A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specif
A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can
SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and
An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter
A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute a
Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnera
A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Arg
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v
CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, w
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0
Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side
SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers
Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endp
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v
Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a
Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo
Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13
openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any g
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a use
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started