57,566 vulnerabilities published in 2026
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to
Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans
Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces
ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.c
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the
A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when t
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta
A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of th
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord butto
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCa
A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules.
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file h
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function va
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a
Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromis
Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace d
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skip
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC
mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package sourc
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the tem
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user cou
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Folde
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/pre
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started