57,566 vulnerabilities published in 2026
The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows o
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona
A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f
A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file
A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulne
The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creati
The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email fo
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared
Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its
The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unkno
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unkno
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allo
A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the fi
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user c
SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function h
In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existenc
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic
CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i
The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and
The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin
The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started