57,566 vulnerabilities published in 2026
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe
The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sal
The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Techno
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a control
The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email c
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote au
When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused b
An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of
An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an
An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentica
An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to b
A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process
A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0,
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th
Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authent
A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown
A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_c
A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_m
A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/na
A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_
A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of t
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a mani
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language M
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th
EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started