57,566 vulnerabilities published in 2026
boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cust
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflo
llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup
diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders,
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with
In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM relate
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows ad
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started