57,566 vulnerabilities published in 2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convin
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability.
WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input a
Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious sc
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated sende
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox
An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su
A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /
A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file inter
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A m
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup
Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers
A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data F
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da
Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce
NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe
React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabl
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malic
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticat
WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attack
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attacker
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. I
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In ve
Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to in
Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform U
Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass na
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attac
A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invok
A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAc
A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user
Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 version
Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0
A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd48
Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker t
Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform
Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issu
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started