57,566 vulnerabilities published in 2026
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the
The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membershi
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling S
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission reso
OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A low
OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Fe
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that a
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurati
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downl
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that al
An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a ne
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a ne
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to pe
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.1
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a ne
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without
A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and
PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes sc
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, w
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string express
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-a
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oau
Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-d
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling function
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started