57,566 vulnerabilities published in 2026
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a
Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built
The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje
The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object
The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to
The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP
KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl
The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec
Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t
Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat
ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho
OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w
ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol
The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing
A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nb
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem
IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and inef
A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started