57,566 vulnerabilities published in 2026
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifyin
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be
IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of servi
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow
Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary
The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers
WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrar
WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attacke
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in
An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service
An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attacker
An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names cont
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)
Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to
An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is gi
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template en
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started