57,566 vulnerabilities published in 2026
Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati
Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malici
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter i
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo
WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Travers
The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Inje
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ge
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all
The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthoriz
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the
The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a
The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in
Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and
Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy confi
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking
The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu
The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce
The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions
An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
An improper access check allows privileged users to overwrite media files without editing permissions.
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started