57,566 vulnerabilities published in 2026
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef
A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce va
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of i
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden
The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec
The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem
The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi
Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e
A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adj
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when return
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th
Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.
The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S
Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop
marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat
Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started