57,566 vulnerabilities published in 2026
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .Req
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w
Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in t
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data'
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page
MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inje
MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows atta
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user c
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/
Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_s
A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `Agen
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability
The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vul
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can el
A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the compon
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t
web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/template
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Bina
Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Re
Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and sc
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box
The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA
Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in
Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.aja
BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. V
An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 th
The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site S
Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/
The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started