57,566 vulnerabilities published in 2026
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp a
Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote
Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private reposi
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a den
NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/ag
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to
The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, an
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypas
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plu
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass
A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function o
A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function S
A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x.
A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipu
The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of i
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Inco
A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an
A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the f
A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown co
A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This
PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin us
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSorting
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started