57,566 vulnerabilities published in 2026
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A
OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic
Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints
A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Q
Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-E
Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-im
A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS mod
AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item iden
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clus
OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces
Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc
gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t
Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19,
Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19,
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauth
Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalati
Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoin
Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated
picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allow
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replicatio
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstAct
A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy
The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authenticatio
Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using
Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (i
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig
An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canaryt
A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4
AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac
The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a
Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p
The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C
Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow.
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started