57,566 vulnerabilities published in 2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access m
IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker
A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewal
SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort para
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel.
The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i
Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker
Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ativ
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remo
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) co
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator
A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high pr
CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=ord
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th
The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet
The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Sto
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec
OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view
The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi
Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started