57,566 vulnerabilities published in 2026
A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS
SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g
SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At
SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the
In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie
NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a
djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated
In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar
Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp
Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to i
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started