2026
57,566 vulnerabilities published in 2026
A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of t
A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1
BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the m
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, u
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template c
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a cr
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits inst
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica
SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileg
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_s
Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Support
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Sprin
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut
Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affe
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing ma
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supp
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail
HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers
Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started