57,566 vulnerabilities published in 2026
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at
Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt
Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpo
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management mod
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When a
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on
Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_tok
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events).
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in
Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to impro
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. Th
Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdo
Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Conten
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without outp
Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or s
A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service
A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file co
A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown functi
A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor
A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all
A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of t
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Op
A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown funct
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started