57,566 vulnerabilities published in 2026
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / au
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 throu
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function d
Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate fi
A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), M
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att
Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject a
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at
Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI sp
Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had com
Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker w
Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica
n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfigu
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun
MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with t
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert med
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens
RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize
Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execut
The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbit
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c
A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerabilit
Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f
ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all
An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started