57,566 vulnerabilities published in 2026
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized att
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin
SSRF via HTTP Redirect in Repository Migration
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_serv
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The
A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/mo
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR compo
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl
vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a
Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und
vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an
An improper access check allows unauthorized users to access workflow stage and transition information.
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr
Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()
Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consu
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re
Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing a
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authen
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Sk
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started