57,566 vulnerabilities published in 2026
A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont
Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription
A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WT
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a
A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the
CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user
The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi
The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability
The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started