57,566 vulnerabilities published in 2026
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on a
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict acc
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its p
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of serv
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification m
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which RE
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in req
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8
The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway w
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco
A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of t
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an aut
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or creden
The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through
The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set uncondit
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prio
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall o
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A m
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attac
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register(
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass i
The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass i
vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON seri
Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strin
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication ru
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization an
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, al
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started