57,566 vulnerabilities published in 2026
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion i
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered
There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators,
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks m
aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the hand
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor
Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX
The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user accoun
A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows una
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows auth
A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/pa
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing auth
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate
Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embed
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th
Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro al
Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Con
A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and e
A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip
In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sen
The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in a
The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versi
The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started