57,566 vulnerabilities published in 2026
Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker
Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to by
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comp
Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to pe
Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform U
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attack
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cros
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboa
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored cust
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX hand
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking
The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an
The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire
FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce
ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP
The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 a
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending me
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started