57,566 vulnerabilities published in 2026
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to e
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary c
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote
AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717
uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an auth
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised acce
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni
Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun
URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API requ
A validation vulnerability has been identified in certain web features related to file management or upload in several p
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code i
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cros
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Requ
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st
FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticate
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `Client
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product fi
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stor
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de
The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started