57,566 vulnerabilities published in 2026
A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file pl
A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component I
A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar.
A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of th
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain condi
The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputt
A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigaw
A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/sr
A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item.
A vulnerability was determined in code-projects Coaching Management System 1.0. Affected by this vulnerability is an unk
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the func
A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/
A vulnerability was determined in kerwincui FastBee up to 1.2.1. The impacted element is the function Add of the file sp
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co
Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio
A vulnerability was found in Dotouch XproUPF 2.0.0-release-088aa7c4. This impacts the function vlib_worker_loop in the l
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the P
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response UR
A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipu
A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an
A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This
A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some un
Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.2
An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated c
An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Met
A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16
A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function crea
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the func
A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessag
Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privil
A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the fi
A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/
A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functional
A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affec
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln
The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state
The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started