57,566 vulnerabilities published in 2026
Tanium addressed an improper input validation vulnerability in Discover.
A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshE
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve s
Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file i
The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v
The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including,
Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.63
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnera
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` a
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could e
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publ
Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administra
Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=de
Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view
Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_
Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_servic
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL p
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserRe
Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Confi
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc
Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `get
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a c
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post E
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,
The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including,
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creatio
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security applianc
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API acce
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started