57,566 vulnerabilities published in 2026
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is
n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excess
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated u
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This i
Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a
MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m
Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/all
Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects
Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph
WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint,
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralizatio
A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of
A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the fun
A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file
A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key
A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log
A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulner
A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/f
A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_
A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Ex
A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of t
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started