57,566 vulnerabilities published in 2026
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a
Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code ex
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could r
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves upl
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) c
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives.
pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submissio
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-
Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive b
Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor ric
Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extract
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a group
DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScr
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a s
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) comm
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Ad
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects th
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Applia
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could e
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi
Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18
GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the a
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders
NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored c
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored c
RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a store
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started