57,566 vulnerabilities published in 2026
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans).
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of th
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through e
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API,
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one
Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository
pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca
Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabilit
Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabili
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and
Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able
Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-loc
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer
Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi
The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po
Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy
The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started