57,566 vulnerabilities published in 2026
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content"
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi
In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive
GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manip
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authentic
A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the
A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op
A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /l
A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an unt
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint ac
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d
A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delst
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate
IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or sessi
A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the li
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library st
A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the l
A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file s
A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/deco
A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown f
A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the compone
A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. Thi
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the medi
prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media genera
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas
Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the
A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packa
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtil
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started