57,566 vulnerabilities published in 2026
The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_serve
Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Functi
Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cl
Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Sp
Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Func
Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Fu
Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0
Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cl
Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Clou
Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stre
Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud
None None None No publicly available exploits are known.
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the confi
Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the acco
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes ano
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cl
filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to w
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attacker
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographi
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (P
An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit
ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard con
HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho
Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite"
In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredu
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an inter
MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyz
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the pr
Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publis
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts
Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to impr
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started