57,566 vulnerabilities published in 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custo
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad
A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function Asse
A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of th
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicio
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported v
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated user
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped fo
Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.
A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::opera
A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file
A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory
A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of
Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil
A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function
A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/m
A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an un
A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/
A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an un
A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknow
A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_si
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functio
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga
A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the fil
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown f
UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect avai
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed func
PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check aft
A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the co
A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.L
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static
A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started