57,566 vulnerabilities published in 2026
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version
In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston
Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number o
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 version
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret
Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPa
A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6
The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 an
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 an
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.
The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo
Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cl
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated
Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an
The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl
VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started