57,566 vulnerabilities published in 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function
A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace
APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up
Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat
External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t
A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file commo
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log
A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for Word
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started