57,566 vulnerabilities published in 2026
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-re
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Webhook Authorization Header Returned in Plaintext via API
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traver
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before ass
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t
In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c
In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta
In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo
Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify eve
The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al
The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p
SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar a
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w
A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo
HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us
A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.toby
A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the
A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose
GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18
HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive
Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce
Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 an
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started