57,566 vulnerabilities published in 2026
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names du
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file pa
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overal
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credenti
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials looku
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overa
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permissio
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to
Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission
Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user
A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue
A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f
When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_
Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h
OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated us
The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe
A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont
Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription
A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WT
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a
A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started