57,566 vulnerabilities published in 2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules.
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file h
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function va
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a
Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromis
Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace d
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skip
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC
mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package sourc
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the tem
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user cou
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Folde
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/pre
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a re
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSS
Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul
A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDo
AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re
GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled f
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based p
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdo
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who
Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote a
Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the re
Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker w
Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacke
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a l
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ
A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re
The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain pot
Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denia
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd
A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_r
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f
A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started