57,566 vulnerabilities published in 2026
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown
A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of t
The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o
In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote informa
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi
Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept
A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of th
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin
Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image render
A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code o
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown proces
A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be
A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This a
A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer:
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all
A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. Thi
A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra
A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of t
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A
Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack
A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security F
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin
Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to le
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi
The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin
A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started