57,566 vulnerabilities published in 2026
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa
In the Linux kernel, the following vulnerability has been resolved: drm/msm/snapshot: fix dumping of the unaligned regi
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler`
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Applicatio
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applic
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Su
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: I
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench)
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supporte
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The end
In the Linux kernel, the following vulnerability has been resolved: hwrng: virtio: clamp device-reported used.len at co
In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate resolution_count and fix WIN8
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only acc
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea
The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity
A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authent
A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started