57,566 vulnerabilities published in 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability
malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve priva
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored i
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and m
Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0.
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow
The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on
SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the e
SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, le
SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses
Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unau
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() end
A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Fir
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacke
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive S
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handle
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffi
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik
Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privile
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability
ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti
Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator
Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent
Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in
dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c
MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc
The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started