57,566 vulnerabilities published in 2026
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel.
The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i
Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker
Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ativ
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remo
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) co
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator
A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high pr
CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=ord
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th
The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet
The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Sto
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec
OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view
The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi
Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.
Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati
Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malici
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter i
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo
WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Travers
The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Inje
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started