57,566 vulnerabilities published in 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipu
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Co
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on manag
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva
Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied inpu
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kiba
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized oper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v
SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint tha
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The real
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves th
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoin
A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of rec
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.t
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due t
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated
The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' paramete
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Secon
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some o
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism,
The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all version
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injectio
The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vul
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeate
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, all
The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'or
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forg
Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_r
stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChann
Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass exis
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started