57,566 vulnerabilities published in 2026
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allow
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw
Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb
Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to ar
tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize
Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchroni
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data
A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject a
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arb
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re
Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypa
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote att
Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started