57,566 vulnerabilities published in 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). Suppor
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applic
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin mid
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows un
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issu
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbo
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configur
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau
CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w
Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i
The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started