57,566 vulnerabilities published in 2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di
A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa
The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/e
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent
The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started