57,566 vulnerabilities published in 2026
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's s
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 th
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password r
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome
: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (develop
: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control v
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path t
In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command inste
In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MS
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't norm
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt aff
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in try_get_locked_pte(
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started