57,566 vulnerabilities published in 2026
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the
WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkE
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili
A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue a
EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on
Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::from
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vu
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to
Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans
Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces
ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.c
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the
A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when t
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta
A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of th
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord butto
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCa
A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started