57,566 vulnerabilities published in 2026
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app
Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without us
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the
A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_
The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, a
The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi
The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers
The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu
A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_fo
A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the fi
A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component
A security vulnerability has been detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The affecte
A vulnerability was detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The impacted element is t
A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageF
A flaw has been found in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. This affects the function rtsp_p
A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of t
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSeg
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::stri
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerabili
A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notificati
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to
A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file
A flaw has been found in birkir prime up to 0.4.0.beta.0. Impacted is an unknown function of the file /graphql of the co
A vulnerability has been found in birkir prime up to 0.4.0.beta.0. The affected element is an unknown function of the fi
A vulnerability was found in birkir prime up to 0.4.0.beta.0. The impacted element is an unknown function of the file /g
A vulnerability was determined in birkir prime up to 0.4.0.beta.0. This affects an unknown function of the file /graphql
A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql
File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview,
Swift W3C TraceContext is a Swift implementation of the W3C Trace Context standard, and Swift OTel is an OpenTelemetry P
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The
The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W
The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss
The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo
IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks agains
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported vers
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Pl
A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticat
GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attac
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta
The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterpr
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modificati
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started