57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v
The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea p
ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu
The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja
Use after free in DNS Server allows an authorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized at
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute cod
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Conn
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supporte
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp
Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Oper
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Sec
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accep
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network int
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f
The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g
Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started