57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The
Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Ope
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versio
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated.
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D
A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bound
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access a
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename hand
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, wh
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup
Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multip
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/repo
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through t
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started