57,566 vulnerabilities published in 2026
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn
Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr
The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of th
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are aff
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1
There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop appli
An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerab
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the in
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the
Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model incl
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0,
The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackS
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi
Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administr
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/
IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticat
Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f
SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1
Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts,
Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects
Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Securit
in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started