57,566 vulnerabilities published in 2026
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au
A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controll
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format st
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper pr
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to v
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all ve
In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sct
In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk ad
In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list i
In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index bef
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_
In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic
In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tai
In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc() di
In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its ti
In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer in
In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP
In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started