57,566 vulnerabilities published in 2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issu
svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering ou
svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XS
svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side render
GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploa
A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. T
LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting v
A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFi
A weakness has been identified in qinming99 dst-admin up to 1.5.0. This impacts the function deleteBackup of the file sr
Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, a
Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The
Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a us
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Gener
OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.
TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS)
Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Script
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite a
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly esca
Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via U
Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker
A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event M
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy`
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access c
A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can injec
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can stor
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge,
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists i
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor r
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via
IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rend
The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa
WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the follow
A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL)
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can ge
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to i
A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs.
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCo
Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started