57,566 vulnerabilities published in 2026
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary
Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help
SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain se
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w
SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the funct
The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the Woo
A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAu
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code o
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the fil
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re
A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS
SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g
SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At
SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started