57,566 vulnerabilities published in 2026
The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3
The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including
The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includi
Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In
Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp
Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co
Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by
The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu
The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option.
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity de
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This
The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content m
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by
A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec o
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea.
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R
Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication,
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue
A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena S
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han
Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa
A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function
OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingre
OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that a
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Em
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10,
Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started