57,566 vulnerabilities published in 2026
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc
Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller
In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor N
A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the
A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_conte
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in a
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of t
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the fi
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: thr
APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso
The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauth
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaus
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capab
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowi
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns t
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to buil
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_s
SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the N
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes l
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec
Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and th
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrep
pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.val
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata f
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a t
browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta
A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the compo
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-vi
A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component N
A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_han
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started