57,566 vulnerabilities published in 2026
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability
The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr
JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens
A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat a
Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login
The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web
An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App:
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame
The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1
The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to
PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website wh
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the Clum
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its log
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and ses
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack
A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file bl
A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/dele
SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user m
SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource no
SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF
Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`
A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to
In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes
OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versi
The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started