57,566 vulnerabilities published in 2026
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenti
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authentica
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated att
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crat
A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to S
Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac
Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (cu
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-dr
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose ki
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the ope
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's ku
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane co
Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts u
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builde
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/u
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on U
Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop i
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/w
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS ge
Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline install
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cro
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests con
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` s
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an
A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user
An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Li
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enabl
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privil
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS device
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attac
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (Mi
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started