57,566 vulnerabilities published in 2026
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser
OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth
Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with onl
Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu
Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_m
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c
SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated u
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php comp
Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This
Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged act
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and
Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu
Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnera
Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey".
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas
Insufficient Validation of Names During AXFR
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove pass
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability ex
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and p
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an ove
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa
Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook serv
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjec
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12,
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/ov
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null c
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started