57,566 vulnerabilities published in 2026
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.
Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12,
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison
In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv
In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This cou
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and
Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten
Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do
Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access.
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started