57,566 vulnerabilities published in 2026
Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payl
Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads
Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts i
Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payload
StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was ide
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privi
The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Fl
GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator c
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows
Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter
VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that a
AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this
Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart
Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parame
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.p
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored
SQL Injection vulnerability in the Structure for Admin authenticated user
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_ma
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated atta
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was fo
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php o
The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a
The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escal
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input valida
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu
The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t
A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface
A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the
A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration modu
A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restora
A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN clie
The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext r
A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabri
A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows a
School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitr
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerab
A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s
The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started