57,566 vulnerabilities published in 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with
In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM relate
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows ad
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template
Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu
An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer
A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI
A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started