57,566 vulnerabilities published in 2026
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the r
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. Th
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, sever
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use
PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the l
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the A
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust j
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un
Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma
The system stores the username and password from the login form after submitting the request. This could allow an attack
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject
Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl
The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard
Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab
A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affe
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server version
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started