57,566 vulnerabilities published in 2026
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the
PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key optio
PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD us
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=
A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market
A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could al
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at
A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo
A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools
A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_net_get/claw_net_post
A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of
A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of th
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of th
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerabi
A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file cla
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/se
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpl
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unkn
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of
In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush p
In the Linux kernel, the following vulnerability has been resolved: xfrm: route MIGRATE notifications to caller's netns
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate Add Extended Advertising
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl
A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side an
A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/up
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jqu
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/fu
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_upload
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unkn
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Su
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started