57,566 vulnerabilities published in 2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Suppor
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reportin
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Po
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functio
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8,
The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.
Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had comprom
Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve
SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality.
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker
Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the fi
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attac
The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendo
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could
The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to ax
The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any addres
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a
A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the compone
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the compone
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the co
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started