57,566 vulnerabilities published in 2026
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar
The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo
The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality,
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, i
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v
A user with access to a valid SAML response may impersonate another user under specific conditions.
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfilt
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of in
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is di
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthen
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_EN
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input se
ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. Th
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random b
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42,
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/pro
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registrat
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart f
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.i
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Subscriber Path Traversal in Do Lasso <= 358 versions.
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Un
Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions
Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checko
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started