2026
57,566 vulnerabilities published in 2026
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to dat
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events)
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Ba
SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissi
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Art
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke
A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious con
This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history
OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown p
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr
Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests whi
GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in
A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the f
Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit p
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end
Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o
Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EX
Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EX
Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_E
Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported ver
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions,
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-mana
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its conne
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started