57,566 vulnerabilities published in 2026
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the
In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie
NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a
djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated
In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar
Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp
Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to i
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Contributor Broken Access Control in uListing <= 2.2.0 versions.
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started