57,566 vulnerabilities published in 2026
Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo M
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin d
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Fire
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Ge
An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Mana
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following')
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name
A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd perm
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to exe
OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execut
OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to exe
OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to ex
GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo
Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme S
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting
A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). T
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatio
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of
In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local e
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6,
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is v
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started