57,566 vulnerabilities published in 2026
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positione
A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file r
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Wi
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate
Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the users
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Log
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds,
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response
A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirr
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76
OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses
Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s
curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond
Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO
Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availabil
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a
A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation
A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p
A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation.
Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta
Concurrency and locking defects in GSS-TSIG
Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYP
Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_V
Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIF
Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started