57,566 vulnerabilities published in 2026
Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibil
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibil
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Su
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due t
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR9
RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c
Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c
The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the G
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some
Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path
An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user,
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeT
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh
The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc
The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor
The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,
The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,
The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled superviso
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote a
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started