57,566 vulnerabilities published in 2026
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi
Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ
A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri
A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to
OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed
Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all
Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by
A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp
Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vuln
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a secu
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classifica
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigat
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist imp
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec
OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that al
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are
OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass works
OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/priv
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does no
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user cou
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started