57,566 vulnerabilities published in 2026
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability
ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti
Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator
Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent
Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in
dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c
MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc
The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a
Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulne
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d
A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAp
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmServi
A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component c
A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAp
A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppRe
A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory o
A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the
A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects som
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sft
A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTe
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som
An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine
An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.
An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated a
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.
Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attac
An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started