2026
57,566 vulnerabilities published in 2026
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processe
Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class
Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays
Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` ac
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perfo
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap
A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary f
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authe
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length fi
GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other securit
In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTT
Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subseque
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose i
openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (S
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Pu
Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,
ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are vario
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-r
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fi
Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "d
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges ove
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authori
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthentica
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using M
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typeb
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an u
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a net
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started