57,566 vulnerabilities published in 2026
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the
A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. Thi
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To
A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aft
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulner
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can byp
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted con
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API e
The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying
The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl
Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.
Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote
Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain pot
Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtai
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, an
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal po
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
Full details and mitigation steps are currently restricted and will be published at a later date.
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started