57,566 vulnerabilities published in 2026
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize()
@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit
Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition
An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versio
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Trave
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inj
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as
WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated att
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect
OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSock
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte c
The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions
An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 128
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec
Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s
Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service w
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no addition
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2
In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe(
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __io
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wi
In the Linux kernel, the following vulnerability has been resolved: jfs: nlink overflow in jfs_rename If nlink is maxi
In the Linux kernel, the following vulnerability has been resolved: udplite: Fix null-ptr-deref in __udp_enqueue_schedu
In the Linux kernel, the following vulnerability has been resolved: rnbd-srv: Zero the rsp buffer before using it Befo
In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frgl
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix "scheduling while atomic" in IPsec M
In the Linux kernel, the following vulnerability has been resolved: atm: fore200e: fix use-after-free in tasklets durin
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate sequence number of TX re
In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS con
In the Linux kernel, the following vulnerability has been resolved: net/rds: Clear reconnect pending bit When cancelin
In the Linux kernel, the following vulnerability has been resolved: ntfs: ->d_compare() must not block ... so don't us
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: move wait_on_sem() out of spinlock With
In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - fix packet extraction from stream When
Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectl
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo
In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started