57,566 vulnerabilities published in 2026
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/e
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent
The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the
A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulat
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetVa
Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromis
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin
The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss
A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the c
A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started