57,566 vulnerabilities published in 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, a
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated a
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conne
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC
Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR
Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa
OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co
go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insuffici
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictio
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a re
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 1
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neu
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creat
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed clu
Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics
Subscriber SQL Injection in Do Lasso <= 358 versions.
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary object
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects d
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the
Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execu
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started