57,566 vulnerabilities published in 2026
Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arb
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S
A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site
Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 throug
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in b
A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /fileman
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs
Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation com
The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including
The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `s
A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edi
A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_us
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organ
Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media u
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s
GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows
Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in
OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-beari
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, det
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect act
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapsho
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported ve
Vulnerability in Oracle Fusion Middleware (component: Dynamic Monitoring Service). Supported versions that are affected
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page,
WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim ope
An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution wh
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `saf
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitr
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` paramet
OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allo
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direc
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scop
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started