57,566 vulnerabilities published in 2026
OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cros
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.
OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.ph
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" p
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attac
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros
OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in
In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the a
A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file wri
NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorre
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment varia
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php all
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your Al
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User F
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force O
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amel
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMai
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woo
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the serv
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with a
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar
Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 throu
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started