57,566 vulnerabilities published in 2026
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to aut
In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-M
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul
TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality.
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authoriz
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s devi
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constr
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-202
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-se
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in th
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gate
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/ser
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknow
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugin
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to ex
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial
Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery.
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbit
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started