57,566 vulnerabilities published in 2026
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
SQL Injection affecting the Access Manager role.
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up t
The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c
Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec
Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-own
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path t
A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can
OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo
FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a phys
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec
Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect ava
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported v
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported ver
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the d
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a
The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a s
OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/inte
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started