57,566 vulnerabilities published in 2026
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?ac
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provid
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::Inse
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decom
A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/conn
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability af
REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retr
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows
An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to u
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu
badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and b
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attacker
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predef
Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin
The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unautho
The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t
The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1.
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho
The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauth
Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation MediaWiki - VisualData Extension allows
A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a P
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac
Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage fu
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection
A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started