57,566 vulnerabilities published in 2026
srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `F
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` throug
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the v
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5
Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate
Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator u
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to i
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib i
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont
Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack:
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, Mustache navigation templates interpolated configu
NVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disc
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy be
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cros
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface componen
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interf
Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) rende
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secu
mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddres
IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthori
IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative use
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started