57,566 vulnerabilities published in 2026
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember
A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the
A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /
A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. P
CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administra
A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file up
A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php
A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of
A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file
Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Im
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/custo
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admi
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f
In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv
Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-
The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela
Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configu
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Con
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Conf
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Bo
Missing Authorization vulnerability in Andy Ha DEPART depart-deposit-and-part-payment-for-woo allows Exploiting Incorrec
Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This iss
Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Securit
Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact
Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ
Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-12
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was miss
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zamma
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for tick
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /ap
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_ass
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started