57,566 vulnerabilities published in 2026
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handl
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause
NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FAS
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported ve
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are a
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are a
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The sup
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are aff
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In
Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The s
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcureme
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor log
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc.
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started