57,566 vulnerabilities published in 2026
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc
The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SI
Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's
Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi
Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:
RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allow
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all
The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow
Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against int
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <=
Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.
Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.
Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.
Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versio
Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started