57,566 vulnerabilities published in 2026
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown cod
A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/in
A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of th
A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMe
A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand
A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength
SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offl
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordA
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/
setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.2
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att
An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125
Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert
A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/te
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend
A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of t
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 un
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf
A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytdlp_download of the file sr
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deser
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes di
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape th
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include f
libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10
Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Transient DOS while parsing video packets received from the video firmware.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a ses
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started