57,566 vulnerabilities published in 2026
BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard wi
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, mac
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadat
E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard with
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to,
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Softwar
Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.Thi
Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated use
IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an att
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras
Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di
Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitatio
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated
Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.
The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v
The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versi
Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An
mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processin
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference
An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-b
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unau
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge th
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started