57,566 vulnerabilities published in 2026
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool.
A specific administrative endpoint notifications is accessible without proper authentication.
Development and test API endpoints are present that mirror production functionality.
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it thr
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credenti
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown fu
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function o
A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionali
A vulnerability was identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The impacted element is an unknown funct
A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/
A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of
A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/t
A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMag
A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file
A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown function
A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Perform
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function
A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publ
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiti
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allo
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s hand
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attac
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modific
The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including
Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate
Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1
The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started