57,566 vulnerabilities published in 2026
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin
The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out
The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c
FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu
OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr
A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /
A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys
OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir
OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec
Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n
The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified th
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr
Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand
The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand
OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc
Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a
Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.
A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att
Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ
The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started