57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Suppor
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Sec
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th
Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Oper
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center).
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported ve
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image
FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailP
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started