57,566 vulnerabilities published in 2026
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat
ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho
OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w
ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol
The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing
A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nb
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem
IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and inef
A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b
boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cust
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflo
llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup
diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders,
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started