57,566 vulnerabilities published in 2026
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permissio
In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with perm
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could ex
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize
Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template inf
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of wha
TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-contr
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta
A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This a
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP metho
Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. Whe
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while lis
Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass
Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove
OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vul
A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of
A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of t
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/u
A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. A
A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve
The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and
The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started