57,566 vulnerabilities published in 2026
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taki
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13,
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.se
remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,
In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan inte
A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attac
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was genera
Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the l
Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missi
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DS
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thund
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting a
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Deployment
Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). S
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S
Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (compon
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operatio
Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Ap
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm c
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on
JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressi
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands
Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started