57,566 vulnerabilities published in 2026
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id
Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in t
OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function wi
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b
The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version
There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti
The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER
Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing informa
Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that
Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows
Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t
A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bu
The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account v
The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a
js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted c
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unkno
opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetr
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t
@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function
Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778
Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture
Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigne
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_mak
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi
The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7.
The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a
The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions
The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modifi
The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorizati
The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure i
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started