57,566 vulnerabilities published in 2026
Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which c
OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) r
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject
Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne
Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface.
PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV impo
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex again
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privilege
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,
Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersiz
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil
Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts return
TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Ora
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecu
The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the au
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade I
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_searc
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could c
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools incl
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php th
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested Ser
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolut
The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crm
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started