57,566 vulnerabilities published in 2026
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User
pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress
The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff
A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Re
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di
A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa
The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started