57,566 vulnerabilities published in 2026
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all version
The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions u
The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve
Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that ret
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFI
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in t
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain
A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section
A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the fil
A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function v
A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the c
Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote
A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the fi
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected
Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured A
Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Co
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exp
Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Con
Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Confi
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-re
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Ele
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-sea
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the
Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica
Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t
A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file o
The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versi
A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor
A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line,
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a n
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate p
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service i
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.
A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function e
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started