57,566 vulnerabilities published in 2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth:
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server.
The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al
The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a
Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio
TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock in
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impo
The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before con
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig
A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Perfo
A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Ex
A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipul
A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th
A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co
A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e
The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i
The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri
Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-
Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir
Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th
The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started