57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation th
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise d
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A te
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integr
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper ce
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information o
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissi
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are pr
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Matterm
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attack
Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses un
Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer p
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesyste
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto de
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine t
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST AP
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor reso
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpo
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vC
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul
OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access fu
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9
A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient ser
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny
HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attac
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started