57,566 vulnerabilities published in 2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano
The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va
SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A
The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature ov
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing
A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout
A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si
The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.
An unauthenticated user may access restricted repository information under specific conditions.
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in
An unauthenticated user may bypass authentication under specific cache conditions.
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 1
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that retu
Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the fa
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session wi
Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of servic
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_functi
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-statu
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protect
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started