57,566 vulnerabilities published in 2026
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Laun
Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command process
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amo
OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-sec
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in th
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i
An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer
Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplyin
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validati
OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/
Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf
The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijackin
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions i
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade
Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi
Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when expli
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerabi
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative clo
JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Mi
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party oper
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromi
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a re
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started