57,566 vulnerabilities published in 2026
The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a
MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publ
A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the fil
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-c
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta
jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco
An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8,
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amp
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec
Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1
In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf
NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNS
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purp
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets t
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a quer
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Floodin
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthent
Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacke
Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Sec
Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the publ
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public sou
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does no
In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php all
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns th
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms exist
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configur
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in s
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c
For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when
The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started