57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF I
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocomm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Re
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme
Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configure
Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting
Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatB
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce all
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box W
Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inser
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooComm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins Suppor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision En
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons
ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admi
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. Th
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer w
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing o
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started