57,566 vulnerabilities published in 2026
n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger
NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where hand
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel sende
An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and th
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Dev
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with htt
The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes bef
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site sc
Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read pe
A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attac
A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overal
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allow
A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and ea
A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to c
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch mis
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied C
Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where att
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id par
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security config
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulne
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and ea
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revi
A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / au
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 throu
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function d
Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate fi
A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), M
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att
Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started