57,566 vulnerabilities published in 2026
Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat
Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, w
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated us
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Gi
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operati
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When
n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenti
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in
Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c acce
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[]
Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen va
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupw
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimbal
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vi
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runti
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected t
Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a
Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R)
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(
Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow a
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started