57,566 vulnerabilities published in 2026
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC
PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows
An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related
An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary
The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, a
A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p
Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut
Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kes
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at
Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr
AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that
Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5,
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dum
Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values fro
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcrip
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allo
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomed
SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getD
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement ro
MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows re
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked th
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the c
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started