57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operatio
Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Su
Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versio
Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versio
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string para
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecti
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it i
The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pas
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an
ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUN
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm use
FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The ke
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.
Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a p
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can pla
In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk r
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authentic
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authentic
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles coul
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started