57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Linear Asset Mana
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engin
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to
Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9
Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js re
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several p
An authenticated user may initiate repository migration operations without required repository permissions, potentially
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bl
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device mo
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privil
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commo
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client s
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint tha
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_h
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil
An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to com
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect
An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attacker
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior
Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allo
Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Confi
Missing Authorization vulnerability in codepeople Sell Downloads sell-downloads allows Exploiting Incorrectly Configured
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a
Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started