57,566 vulnerabilities published in 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem
Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ve
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5
SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExpor
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to cra
A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file sr
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose
A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem
Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder
Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de
An attacker can modify data that should be restricted to read‑only access.
Weintek cMT3092X HMI stores user account passwords in plaintext.
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version
In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston
Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number o
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 version
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started