57,566 vulnerabilities published in 2026
IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniqu
IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh Hurr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGall
Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Galler
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesof
Missing Authorization vulnerability in vertim Schedula schedula-smart-appointment-booking allows Exploiting Incorrectly
Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F
Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but d
An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s
Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit,
ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" secu
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be h
VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malic
Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functio
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au
IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru
IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recur
A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Acce
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect a
OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof
IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started