57,566 vulnerabilities published in 2026
IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use ra
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to
SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers auth
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP In
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVG
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerabi
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are a
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: I
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All
Contributor SQL Injection in eRoom <= 1.7.1 versions.
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started