57,566 vulnerabilities published in 2026
A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of
A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the function Assimp::Compre
A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter:
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the fi
A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown f
A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the fil
A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is t
A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function
A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the func
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignm
A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executin
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f
A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/
A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController
ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP serv
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/
Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca
Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and
Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates
Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is so
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported ve
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewS
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazeli
Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing a
Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/wor
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the functio
A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dial
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /view
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unkn
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affec
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file
The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value bein
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started