57,566 vulnerabilities published in 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to c
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /
Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (age
Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Supported versions th
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affec
Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file mana
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in m
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to in
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a net
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP reque
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege att
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 1
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backen
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resol
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data U
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a spe
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started