57,566 vulnerabilities published in 2026
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated r
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the w
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lac
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file acc
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive informatio
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially c
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough r
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session ope
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylo
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attacker
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication,
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and i
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers t
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which pro
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web ser
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService all
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Ne
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed O
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secr
Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's
EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors
EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates
EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes`
Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 1
An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive informati
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose inf
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to dis
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started