57,566 vulnerabilities published in 2026
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that al
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized wit
Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and
LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Sc
In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered wit
OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a s
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to laun
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co.
Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnera
A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16
Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated use
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 1
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib cl
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cro
Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 1
OpenEMR is a free and open source electronic health records and medical practice management application. Users with the
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more
baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to
A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat
A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a sto
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handl
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity
KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sig
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently del
ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability
ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerabili
ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-suppl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started