57,566 vulnerabilities published in 2026
HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component con
Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (m
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc
GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i
Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource L
Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functiona
Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers
A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability ex
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users ca
A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre
The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administ
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows
The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to th
The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transf
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.
phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `ap
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypas
The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST
Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Suppo
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns
The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as pa
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started