57,566 vulnerabilities published in 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes t
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u
The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving o
The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in al
The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Emb
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to t
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a D
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f
GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthentica
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct
The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi
Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated at
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modifi
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password use
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify t
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and the
Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-le
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recu
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization tha
Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT
Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler
The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an
The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 vi
Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attac
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started