57,566 vulnerabilities published in 2026
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, Fort
DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fe
The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl
The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rend
Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{I
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat De
A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defen
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated,
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated,
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which
Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated,
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthentica
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthentica
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def
Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allow
Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V
Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges cou
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array le
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect
Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af5
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i
The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, whic
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP ha
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url
An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization
An issue that allowed administrators to create and update users outside of their authorized organization scope has been
An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco
An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started