57,566 vulnerabilities published in 2026
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromi
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI sp
Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform U
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars e
Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, the
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X
WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject ar
WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers t
docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) v
HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fi
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassi
OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent c
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legac
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure
Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b
Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), a
A configuration file on the local file system had improper input validation which could allow code execution and potenti
Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The f
An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiN
Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their a
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all v
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: So
Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applica
Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the
ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain condi
podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints wher
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. T
HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con
Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started