57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module r
Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability
CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before
In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization
Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe
The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte
use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,
goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system
Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged us
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server
use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva
When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac
A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP
TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph
TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic
TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauth
TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath accepted by apps/dokp
react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau
Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e
In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain
Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher
Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex
Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first
Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started