57,566 vulnerabilities published in 2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper ne
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr
Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplie
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 vers
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 vers
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial V
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - C
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intend
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the int
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the r
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2pro
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Repository Visibility Manipulation via Git Push Options
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exp
IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to e
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any auth
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Acc
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Flee
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet re
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Stor
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from th
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started