57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a diffe
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Don't leak PFN when kvm_translate_vncr(
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1
A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of
Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl
A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t
A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunctio
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi
ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstan
Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an
rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registra
A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/custome
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function sa
A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing o
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the fil
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated requ
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _trans
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started