57,566 vulnerabilities published in 2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporte
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of se
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values be
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g
The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head
YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read l
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect avai
FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administra
IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text bloc
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of m
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a
stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started