2026
57,566 vulnerabilities published in 2026
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS C
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects).
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Int
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Sec
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request hand
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, al
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically wit
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to ex
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stor
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to s
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file ass
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co.
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to t
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Adm
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input o
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /ses
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CR
A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulne
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started