57,566 vulnerabilities published in 2026
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat
tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return
datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of serv
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submiss
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo
The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che
The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions
Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat
The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndD
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun
The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use
Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remo
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated em
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon
A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::in
A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the fi
A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/a
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmau
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started