57,566 vulnerabilities published in 2026
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Pay
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operatio
Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potential
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under
With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queri
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip:
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:'
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 asserti
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versi
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that all
IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validat
Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handl
Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apa
Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects A
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 t
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun
nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a w
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr
FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started