57,566 vulnerabilities published in 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu
badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and b
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attacker
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predef
Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin
The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho
The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t
The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1.
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho
The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauth
Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation MediaWiki - VisualData Extension allows
A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a P
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac
Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage fu
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection
A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option
When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl
Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Secur
NiceGUI is a Python-based UI framework. From versions v2.10.0 to 3.4.1, an unauthenticated attacker can exhaust Redis co
Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of v
The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from
Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictiona
Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Level
Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beav
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows p
A vulnerability has been found in TOTOLINK WA1200 5.9c.2914. The impacted element is an unknown function of the file cst
The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorizat
Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bou
The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started