57,566 vulnerabilities published in 2026
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco
Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabl
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cro
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injectio
Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
Administrator SQL Injection in WP All Import <= 4.0.1 versions.
Administrator SQL Injection in Popup box <= 6.0.1 versions.
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type
Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API u
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v
In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap,
FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trus
FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling.
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw
LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.1
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access r
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted a
Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorizat
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti
SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in iee
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported version
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started