57,566 vulnerabilities published in 2026
Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulne
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d
A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAp
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmServi
A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component c
A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAp
A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppRe
A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory o
A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the
A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects som
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sft
A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTe
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som
An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine
An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.
An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated a
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.
Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attac
An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit f
file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, u
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipula
Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does n
Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerabi
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/acc
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Serv
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded r
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca
ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-suppl
Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navig
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started