57,566 vulnerabilities published in 2026
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id acce
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortc
Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js
Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download
Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments a
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via une
Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hoo
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App:
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly co
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a mali
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter proces
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically cra
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically craft
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/sc
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnera
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether th
The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoi
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read ac
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HT
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INIT
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct pat
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - A
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim co
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of
@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-r
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with th
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of out
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementat
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started