57,566 vulnerabilities published in 2026
Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saeros1984 Neoforu
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid no
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows rem
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su
Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnera
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumer
TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass
PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database informat
The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them bac
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF
The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions
PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers
PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows r
GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calend
In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix potential OOB access in audio mixe
In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices
In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Fix restoration of SVE contex
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to
RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers t
thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries th
TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate databas
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, da
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to befor
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers
eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows atta
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executio
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet Forti
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper acces
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iP
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early read unlock of page with EOF in mi
In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: fix out-of-range access o
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: use skb_header_pointer_careful(
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vul
lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field pass
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started