57,566 vulnerabilities published in 2026
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/get
A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the fil
IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to s
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50
Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero Data Loss Recovery Applian
A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsi
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Asser
Tanium addressed an improper access controls vulnerability in Interact.
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could h
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handl
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensiti
A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes
Tanium addressed an improper access controls vulnerability in Interact.
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPad
Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially w
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the c
A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code
A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. Th
wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calli
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf
A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unkno
A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the comp
A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown fun
A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the
A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionali
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated u
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache
Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are
A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPor
A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Car
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /w
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating t
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a m
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started