57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access
Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elem
Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-deliver
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple F
@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection
Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to
When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimete
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo
A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in
An improper access control vulnerability exists where an authenticated user could access areas outside of their authoriz
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat
Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed ke
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensiti
Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially s
Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset all
An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data acces
A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive use
An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab acces
Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SS
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (def
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an au
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen
Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG`
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP ser
A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to
A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive info
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in
OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vuln
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started