57,566 vulnerabilities published in 2026
JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers t
MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary
Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supp
EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execu
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary cod
Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.
HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_
OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerabl
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud ser
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context
Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis
In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al
In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers
Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito
act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and rub
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that
In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions
wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3
An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critica
An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to o
An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite
An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critic
The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message s
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection vi
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started