57,566 vulnerabilities published in 2026
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompres
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where thi
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup
GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API end
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the r
The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati
Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Config
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Au
Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket bac
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1
Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects
Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This i
Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device infor
BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u
A resample query can be used to trigger out-of-memory crashes in Grafana.
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5,
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs aga
The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow w
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Respo
LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-
changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include
pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download e
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Informati
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malform
DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged us
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSoc
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length fie
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can cra
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_up
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started