57,566 vulnerabilities published in 2026
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writin
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Goo
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PD
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vuln
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that res
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf
An authenticated user with limited read privileges may be able to access documents from collections they are not authori
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions -
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forw
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub L
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Im
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started