57,566 vulnerabilities published in 2026
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th
Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of Java
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows at
Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st
The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, wa
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona
Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exis
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler
A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver
OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could in
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539
A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an una
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with
Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a store
In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NULL deref on missing i
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure
OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic lo
SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated
A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the compone
Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS T
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attac
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, an ap
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started