57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows Exploiting Incorrectly
Missing Authorization vulnerability in Trusona Trusona for WordPress trusona allows Exploiting Incorrectly Configured Ac
Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrect
The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc
The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
The ZT Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.
The Star Review Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl
The Set Bulk Post Categories plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
The Login Page Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for
The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca
The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) pr
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client
EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated u
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modif
pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is pre
The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct O
The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version
The imwptip plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.
The Bitcoin Donate Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in
The Change WP URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPad
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an app
A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionalit
Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low pri
A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected ele
A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted ele
Tanium addressed an improper access controls vulnerability in Tanium Server.
Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file r
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensi
The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1
A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /
A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the
A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. Th
The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, whi
IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/GlobalContribut
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/Imp
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started