57,566 vulnerabilities published in 2026
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0,
The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackS
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi
Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administr
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/
IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticat
Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f
SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1
Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts,
Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects
Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Securit
in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3,
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the
WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkE
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili
A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue a
EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on
Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::from
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vu
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started