57,566 vulnerabilities published in 2026
The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm
A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete
The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a
Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitra
Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id
The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-base
Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directori
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbit
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7
The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/vie
Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.
Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password direc
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 an
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentation
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, a
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vul
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulne
The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' p
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows auth
ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, au
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configure
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /c
PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities
PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer derefere
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started