57,566 vulnerabilities published in 2026
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio
The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che
A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impa
A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the
A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of
A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function get
WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthoriz
WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to pe
MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the need for local inst
The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu
Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fi
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 15
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument
OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch
OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wr
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote
In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to
In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to rem
In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote i
Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authentica
Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated
Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Leve
: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Acce
Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Con
Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This iss
Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cro
Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-ori
Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions.
Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticate
A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker t
In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr
The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecur
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Informati
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln
The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,
Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user
SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup
The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started