57,566 vulnerabilities published in 2026
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att
Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market
Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp
ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to b
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be
OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin
OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows aut
OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-con
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host
Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ
An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv
Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo
Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse
Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.
Subscriber Broken Access Control in Motors < 1.4.107 versions.
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.
Subscriber Broken Access Control in myCred <= 3.0.3 versions.
Subscriber Broken Access Control in Amelia <= 2.2 versions.
Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.
Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.
Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started