57,566 vulnerabilities published in 2026
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when wr
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject per
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth f
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_past_sync() c
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_sock_getname Access
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file meta
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported v
Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Test
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface u
Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all
Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux,
Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/s
NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privil
An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .verv
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to acce
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a
This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Cente
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker
Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adver
Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R)
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unaut
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-suppl
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emula
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't int
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started