57,566 vulnerabilities published in 2026
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile
Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r
Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a
Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulne
Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to
Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese
Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in
A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pc
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication
Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu
Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint byp
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A
A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing local privilege escalation to the Reporter service context.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent no
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Reco
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Pyt
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started