57,566 vulnerabilities published in 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versi
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integratio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to vers
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowi
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachabl
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it i
SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup.
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (a
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_d
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authent
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated rem
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Aut
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key bu
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStruc
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce
The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in librar
The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/co
In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthent
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication,
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/get
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started