57,566 vulnerabilities published in 2026
A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 1
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on th
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.
ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, Rep
HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of t
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi
Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`
A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of
A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated att
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the fi
A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such
Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated,
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log f
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configur
The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restriction
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless clie
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does n
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software an
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secur
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acr
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Prot
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyb
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Prot
A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown funct
Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category
The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started