57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromi
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive informatio
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/Exp
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompt
HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmainta
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Acce
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versi
Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeep
A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report T
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file
ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can
Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an informa
Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) withi
Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosu
Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an informati
LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langch
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software
LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Req
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to
Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insuffi
Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie
Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault confi
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale
Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect avail
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availabi
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge
Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role Sys
A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getPar
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access
Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user
A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started