57,566 vulnerabilities published in 2026
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati
A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the
A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct
A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function
A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace
APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up
Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started