57,566 vulnerabilities published in 2026
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper ne
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr
Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplie
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 vers
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 vers
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial V
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - C
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intend
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the int
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the r
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2pro
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Repository Visibility Manipulation via Git Push Options
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exp
IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to e
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any auth
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Acc
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Flee
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet re
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Stor
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started