57,566 vulnerabilities published in 2026
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is on
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed i
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixe
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and
Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI read
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualB
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext withi
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded i
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side c
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or accoun
Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requirin
Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 th
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remo
Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `f
Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the def
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can cra
tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.
The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due
The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In ve
The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart S
esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF v
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticat
Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source por
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 1
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_siz
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereference
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a De
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Servi
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on
TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A v
rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Ver
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can cra
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prio
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started