57,566 vulnerabilities published in 2026
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowin
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>,
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expressio
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) fi
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/s
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-direc
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public R
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied rem
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started