57,566 vulnerabilities published in 2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Connectors and Co
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi
Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supporte
Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supporte
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.
Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix fi
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attribut
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability s
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoin
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attac
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint i
The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in
The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restauran
The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applicati
This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that
An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to var
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result i
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability wh
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file st
jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Sli
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).
AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started