57,566 vulnerabilities published in 2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the
The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM
The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver
The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi
The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and
The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL
The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm
A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete
The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a
Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitra
Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id
The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-base
Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directori
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbit
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7
The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/vie
Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.
Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password direc
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started