57,566 vulnerabilities published in 2026
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `
Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endp
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of use
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether
Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password r
OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Sl
An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allo
Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate p
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillec
Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.1
Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these
Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbir
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict
OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata c
OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that all
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authent
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server).
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor).
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package).
Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Other). The
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The
Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). S
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported
Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench)
Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started