57,566 vulnerabilities published in 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Z
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Lambe
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Lambe
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Lambe
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup AllIn
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio Listi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam RH Frontend
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer D
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesig
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediC
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m
Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli
OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f
OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF
Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are a
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb
Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr
Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL querie
Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary
pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the pu
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studi
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise expose
The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the p
OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generati
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by
Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate databas
Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized vari
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® I
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always
Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not
A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica
A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick
In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys()
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started