57,566 vulnerabilities published in 2026
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization fl
Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lack
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the fi
Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing a
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system.
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh
Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre
An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows a
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an
Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Pri
Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker
libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and
Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner re
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member w
Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat
In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the wor
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-brac
A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the
OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live Event
Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the s
Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to byp
Incorrect security UI in WebAppInstalls in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI
Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perfo
Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau
Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started