57,566 vulnerabilities published in 2026
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the
CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user
The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi
The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability
The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl
Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
An authenticated user may view private Puppet module metadata without repository read access.
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
A bundle writer may create misleading release promotion information under specific conditions.
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API
An authenticated user without repository read permission may access package metadata under specific conditions.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due t
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to imp
GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 1
Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/s
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race c
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started