57,566 vulnerabilities published in 2026
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass
The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca
The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl
The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c
The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged
Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory
Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated
A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to
Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by trickin
Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user
A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the fi
A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unkno
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnera
A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown functio
A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown func
A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the fil
A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown func
A vulnerability has been found in code-projects Employee Management System 1.0. Affected by this issue is some unknown f
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the
Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to del
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of
A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Contro
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This
Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows
Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This i
Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security
A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function a
A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSidePro
A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file pac
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing
Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw ex
e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device
Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypa
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Orig
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID wi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started