57,566 vulnerabilities published in 2026
A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/inde
A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the fi
A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /a
A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/e
A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca
The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown functio
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restric
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to
`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branc
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` throug
iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve
Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` c
Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forg
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content"
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi
In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive
GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manip
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authentic
A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the
A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op
A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /l
A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an unt
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint ac
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started