57,566 vulnerabilities published in 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active
Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configure
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the
in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of serv
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Sm
arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att
SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic paddi
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r
In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach
Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi
Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ
A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri
A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to
OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed
Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all
Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by
A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp
Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started