57,566 vulnerabilities published in 2026
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against
The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `
A repository publisher without delete permission may modify protected package content under specific conditions.
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a
A low-privileged authenticated user may access restricted support information under specific conditions.
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutraliza
Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to s
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fi
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary file
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying th
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secr
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit res
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoi
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started