57,566 vulnerabilities published in 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RF
Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administr
Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface.
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a
The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in
The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis
The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip
IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able
IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin ur
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref
Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized a
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can
Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Devel
A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Perform
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/
A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pf
A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions
A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is
A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of
A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown funct
A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an u
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr
A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeratio
Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,
Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and inclu
A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api
A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public
A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/Download
A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-b
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed
Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started