57,566 vulnerabilities published in 2026
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi
A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync
A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul
A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com
The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on
DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta
Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s
Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names du
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file pa
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overal
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credenti
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials looku
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overa
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permissio
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to
Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission
Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user
A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue
A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f
When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_
Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h
OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated us
The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started