57,566 vulnerabilities published in 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `sma
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp
Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domai
ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta i
ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52,
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s ce
Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration A
The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in versio
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome
Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-e
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook en
Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-on
Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Servi
Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in P
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac
Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL in
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or ma
An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromis
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client s
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for sessio
Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP
HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code i
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wp
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limi
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Transient DOS when MAC configures config id greater than supported maximum value.
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started