57,566 vulnerabilities published in 2026
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser
OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that tru
Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/p
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivat
Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentic
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR)
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing ta
CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk conta
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (m
monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f
GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl
OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicti
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability a
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affec
Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by
Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials
Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking
Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application
OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channe
Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via t
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can creat
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera
Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stor
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall
Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m
Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible f
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started