57,566 vulnerabilities published in 2026
An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an
The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire
FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce
ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP
The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 a
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending me
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi
A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync
A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul
A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com
The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on
DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta
Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s
Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started