57,566 vulnerabilities published in 2026
MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method paramete
A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-b
The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst
The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data
Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj
Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject maliciou
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject maliciou
Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious script
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the
Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issu
Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privileg
A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the fi
A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/form
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly va
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration
BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server
A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. This issue affects the function strcpy of the file
A vulnerability has been found in UTT HiPER 810G up to 1.7.7-1711. Impacted is the function strcpy of the file /goform/s
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG362
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulner
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vi
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects
In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFi
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera
The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to ex
Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.
An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al
Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti
Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S
The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema
Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express
API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al
2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started