57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for mi
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for ma
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the Subta
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability
The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized
The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. T
Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthen
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API key
The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Expos
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thun
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val
The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a
The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all
The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,
The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da
The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error
Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo
Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode
The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker co
BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover cre
The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending du
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft throu
The application discloses all used components, versions and license information to unauthenticated actors, giving attack
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the
Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl par
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has b
The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handle
b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account deta
The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi
The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verifi
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized mo
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions
The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started