57,566 vulnerabilities published in 2026
In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user
During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe
An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the
OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command inje
OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability
Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserM
OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may l
The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation i
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This
GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renamin
GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the
An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit
Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corr
Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to b
Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with a
i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated att
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation
A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject c
The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Elect
The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26
A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote a
In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge no
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior,
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior,
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue aff
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists i
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated adm
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on
Tanium addressed an improper input validation vulnerability in Deploy.
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress
The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all ver
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ
A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpG
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy o
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers o
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started