57,566 vulnerabilities published in 2026
Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. Whe
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while lis
Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass
Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove
OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vul
A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of
A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of t
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/u
A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. A
A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve
The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and
The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T
Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read a
A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceIm
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu
Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy
Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-o
Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy
Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi
Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web
Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin
Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi
Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi
Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web
Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had
Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social
Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soc
Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy
Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote atta
Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social en
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started