57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The su
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The su
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that ar
Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll). Supported versions that
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Su
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Ser
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writin
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Goo
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PD
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vuln
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that res
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf
An authenticated user with limited read privileges may be able to access documents from collections they are not authori
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions -
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started