57,566 vulnerabilities published in 2026
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a
Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UA
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t
OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref
In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr()
OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges
The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonai
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno.
Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re
In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-h
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav
MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Fo
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated,
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when
The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before usin
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quick
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hote
The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request
Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with ex
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment
Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expans
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be f
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started