57,566 vulnerabilities published in 2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireles
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modif
goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t
titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /a
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/sett
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leak
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This i
The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc
RouterOS provides various services that rely on correct verification of client and server certificates to secure confide
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a
OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive
OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that byp
OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository p
OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolve
The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality write
Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session
Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileNam
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers.
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers.
A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated,
Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensit
Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially s
OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows
OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu
Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started