57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security).
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affec
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Interna
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Thi
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admi
A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/pin
The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program h
phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure count
phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAut
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a use-af
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-
A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functional
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attac
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOA
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or a
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can coll
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?met
A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the fil
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bun
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay au
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCo
A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-pat
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects
HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against
The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende
In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/sec
An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintai
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to po
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDec
IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distr
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker
None None None No publicly available exploits are known.
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started