57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allo
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Ex
A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers
A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t
phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly e
The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1
The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi
The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to
A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the
Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t
Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in
The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to
Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /
A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_T
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in htt
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Mid
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve sta
The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in v
The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due
The Simple calendar for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.
The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a
The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
A security flaw has been discovered in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_bearer_resource_fa
A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_be
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF d
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Func
Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: f
During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc
soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice
Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to
SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the bac
A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handl
A vulnerability has been found in Open5GS up to 2.7.6. The affected element is the function sgwc_s11_handle_modify_beare
Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings
Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with
birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att
TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`,
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the fi
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSess
A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /
Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenti
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started