57,566 vulnerabilities published in 2026
A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some
A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attacker
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physi
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindo
HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). Th
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,
Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator m
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a mod
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to co
An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i
Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may
@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for re
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a regist
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
The github_workflows module constructs local directory paths from user-controlled repository names without validating fo
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it
A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allow
In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could le
FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability i
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the com
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started