57,566 vulnerabilities published in 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an
An improper access check allows unauthorized users to access workflow stage and transition information.
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr
Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()
Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consu
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re
Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing a
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authen
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Sk
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpo
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sens
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong
The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve
Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability
Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated
Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake func
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce th
A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/posta
An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started