57,566 vulnerabilities published in 2026
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc
Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a
Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.
A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att
Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ
The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec
A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho
A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us
ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write
A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten
A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp
Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows
The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM
Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started