57,566 vulnerabilities published in 2026
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML
A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh
undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before
undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren
The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using
OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al
Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp
The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at
Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt
Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpo
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management mod
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When a
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on
Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_tok
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events).
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in
Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to impro
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started