57,566 vulnerabilities published in 2026
Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ag
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide
Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Prod
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the valu
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili
NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena
Subscriber SQL Injection in Tourfic <= 2.22.5 versions.
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.
Contributor SQL Injection in Gallery <= 4.7.8 versions.
Contributor SQL Injection in WP Post Author <= 3.9.1 versions.
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started