57,566 vulnerabilities published in 2026
Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's a
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacke
Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access info
SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensiti
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Fir
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. Th
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized m
The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i
Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authenticatio
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially l
An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without
Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions thr
Certain error messages returned by the application expose internal system details that should not be visible to end user
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to e
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listin
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to
The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu
The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D
The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2
The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.
The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. Thi
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking at
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct O
The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to
A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the fi
A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of t
A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performi
A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This v
A vulnerability was detected in technical-laohu mpay up to 1.2.4. This affects an unknown function. Performing a manipul
A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modul
A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code.
OpenProject is an open-source, web-based project management software. When using groups in OpenProject to manage users,
Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulner
Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()`
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in
The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch
EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat
EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,
Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exis
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started