57,566 vulnerabilities published in 2026
The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality write
Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session
Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileNam
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers.
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers.
A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated,
Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensit
Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially s
OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows
OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu
Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use
Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attack
Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as
Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint all
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi
Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1
i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for D
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with reta
Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added i
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started