57,566 vulnerabilities published in 2026
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0,
A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized a
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi
The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at
webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive
webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of s
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo
Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enu
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attac
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted H
The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi
The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec
The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,
The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data
The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c
The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including
The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
A security flaw has been discovered in Open5GS up to 2.7.6. This vulnerability affects the function ogs_gtp2_parse_tft i
A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_re
A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/
A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_conte
A flaw has been found in Open5GS 2.7.6. The impacted element is the function mme_s11_handle_create_session_response of t
A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoi
The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could
IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an un
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that coul
The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v
The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due t
The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check i
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorre
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu
A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of t
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication
In the Linux kernel, the following vulnerability has been resolved: md: suspend array while updating raid_disks via sys
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a
A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impact
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to au
The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions
The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started