57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loadi
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachm
A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality o
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: validate MAP frame length bef
The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct
Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endp
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to
Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticate
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wr
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by
A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown fun
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/u
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm
A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is
A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started