57,566 vulnerabilities published in 2026
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulner
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with per
n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file ac
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git nod
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allo
Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an
OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary
GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function modul
Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install
emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadat
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to
Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gs
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to
Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using
Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the b
OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript mon
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, Oliv
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vu
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits i
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation
Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue aff
OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and ea
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Fil
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a
Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress b
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal appro
Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Pri
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allo
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allo
Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started