57,566 vulnerabilities published in 2026
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP fronten
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of servi
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to es
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker
react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQ
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P
HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th
HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz
Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler ser
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} ch
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The co
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A l
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature byp
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/ge
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the
Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authentic
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t
OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started