57,566 vulnerabilities published in 2026
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to
OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attacke
OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extensi
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydr
OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching acc
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS
OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cybe
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs curren
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks
2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization fl
Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lack
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the fi
Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing a
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system.
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh
Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre
An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows a
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an
Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Pri
Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker
libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started