57,566 vulnerabilities published in 2026
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
Full details and mitigation steps are currently restricted and will be published at a later date.
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User
pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress
The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff
A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Re
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started