57,566 vulnerabilities published in 2026
Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page whi
A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrec
Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Config
Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Fo
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploit
Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.Th
Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allow
Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Reque
Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on a
Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorre
Missing Authorization vulnerability in wpelemento WPElemento Importer wpelemento-importer allows Exploiting Incorrectly
Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface all
Cross-Site Request Forgery (CSRF) vulnerability in themelooks Enter Addons enteraddons allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue
Missing Authorization vulnerability in Nelio Software Nelio Popups nelio-popups allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in WP connect WP Sync for Notion wp-sync-for-notion allows Exploiting Incorrectly Co
GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due
Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the Z
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.
IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/m
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi
HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrativ
Tanium addressed an improper access controls vulnerability in Patch.
Tanium addressed an improper access controls vulnerability in Deploy.
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an improper access controls vulnerability in Reputation.
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the
The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an a
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below th
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administrat
The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the fil
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started