57,566 vulnerabilities published in 2026
Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can en
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pa
OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl
The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and i
Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been d
Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitiv
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe
A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external we
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low
An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() AP
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could upd
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker
Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could m
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold
A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR Pa
CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creat
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attac
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose informa
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a netw
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability
The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr
JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens
A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat a
Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login
The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web
An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App:
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started