57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a re
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSS
Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul
A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDo
AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re
GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled f
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based p
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdo
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who
Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote a
Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the re
Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker w
Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacke
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a l
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ
A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re
The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain pot
Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denia
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd
A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_r
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f
A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov
Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the g
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is en
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability ex
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded i
A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0
In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Window
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unkn
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started