57,566 vulnerabilities published in 2026
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability
A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_datafr
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_h
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_featu
A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_
A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflo
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r
A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.
A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integratio
A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key
A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObserv
Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution
jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read
On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in truste
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, w
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a de
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local back
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl
The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w
A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functi
A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file ro
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functi
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1
On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor
OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-i
A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Con
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t
A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the functio
A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affect
A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affect
A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the fil
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default impl
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started