57,566 vulnerabilities published in 2026
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the fi
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attac
The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendo
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could
The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to ax
The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any addres
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a
A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the compone
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the compone
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the co
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artif
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet
The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and es
Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co
CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in
The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c
An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability,
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started