57,566 vulnerabilities published in 2026
The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization
The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf
Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Severa
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi
Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre
A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p
A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/rou
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached
Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticate
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ads
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication
A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earl
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a pat
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a cra
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protecti
The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1.
The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.
The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t
The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check a
The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu
The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t
The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, an
The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1
Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that all
hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to injec
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allo
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated thro
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers w
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Rea
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secret
A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allow
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Ite
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers wi
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller,
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started