57,566 vulnerabilities published in 2026
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A use
A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability ste
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Secu
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets re
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply
A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to st
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requ
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and ce
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged i
A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connect
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 unti
jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest int
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows
Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa
Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla e
Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocma
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu
Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListContro
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypa
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, Pro
n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in wo
ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed v
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows a
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Curso
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only
FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints unde
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRA
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to
Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security no
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-valid
Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d
Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call Template
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can a
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connecti
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store atta
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling ca
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started