57,566 vulnerabilities published in 2026
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede
JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t
IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1
Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1
DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service
music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in
Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenti
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio
A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe
In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 lib
An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regul
A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensiti
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in th
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function
OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor
Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an
XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du
The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne
A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver
There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud
In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who
OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Go
OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that al
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accep
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unaut
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior
lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, deco
ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug in the handle_trailers function where rejected tra
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started