57,566 vulnerabilities published in 2026
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bound
Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled
A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly
MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in Defaul
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authe
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after use
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path trav
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu
In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm
Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci
A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, rely
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable,
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started