57,566 vulnerabilities published in 2026
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patc
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass v
Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi
Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause
DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authentica
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 unti
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a
FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authentic
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin calle
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed valu
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise an
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HT
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create pe
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, two concurrent token-exchange requests us
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (pack
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with kno
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users s
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequ
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a passwor
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authe
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a ca
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequ
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h
Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) al
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.3
Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows
Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py)
Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exp
Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai
OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.c
A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All plat
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started