57,566 vulnerabilities published in 2026
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /
OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allow
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri
IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mas
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users
IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM
Tanium addressed an incorrect default permissions vulnerability in Performance.
Tanium addressed an incorrect default permissions vulnerability in Patch.
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
Tanium addressed an incorrect default permissions vulnerability in Discover.
Tanium addressed an incorrect default permissions vulnerability in Comply.
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
Tanium addressed an incorrect default permissions vulnerability in Enforce.
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attac
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using p
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any t
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access co
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in th
The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo
C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar
Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with cust
Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or mo
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co.
Crafted delegations or IP fragments can poison cached delegations in Recursor.
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_h
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to fil
Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/
Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started