57,566 vulnerabilities published in 2026
Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys wit
MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not en
Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filt
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL
The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa
Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.
SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right
The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica
varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with role
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any b
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer
Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user ac
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enab
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.acce
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag with
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content t
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts in
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent`
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAge
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent
Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection
Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the priv
Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensit
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files wi
Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persiste
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privil
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started