57,566 vulnerabilities published in 2026
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI
A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) c
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a byp
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform backgrou
OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil
Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg
OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to b
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Po
Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potenti
Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnera
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path
Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug
GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allo
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauth
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perfor
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS con
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the
qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that r
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t
In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (f
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We
The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Ex
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromi
Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the
Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerabili
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to ele
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forge
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This iss
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to en
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele
PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started