57,566 vulnerabilities published in 2026
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an autho
Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a l
In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep
Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attack
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulne
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic
Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prio
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is r
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authentica
Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via th
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows auth
Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp
Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint.
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access cou
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with pe
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the S
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing
The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handl
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp c
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remo
OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attack
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote att
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows r
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started