57,566 vulnerabilities published in 2026
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that
Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a lo
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Applicat
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al
FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior
Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an
DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job
9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requireme
The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter befor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re
Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated a
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result i
Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'
Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability t
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53,
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c
The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching
AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompl
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.
css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb,
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started