57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_UNUSED pte bit The
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to allocate W
In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubufs only once vhost
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down s
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling befo
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stre
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authenticatio
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior t
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and me
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or pro
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can retu
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and mod
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer ove
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys(
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started