57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response
In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks T
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditi
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, co
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
Two SSRF findings in Gitea 1.26.2
A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a confi
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queri
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to rea
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated user
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that all
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to
In the Linux kernel, the following vulnerability has been resolved: PCI: Check ROM header and data structure addr befor
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows auth
In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected with
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaSc
ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing
Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when a
Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The suppo
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events).
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that
Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are a
Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Test
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operat
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started