57,566 vulnerabilities published in 2026
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d
In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a maliciou
In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malic
In display, there is a possible system crash due to use after free. This could lead to local denial of service if a mali
In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malic
The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi
A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper valida
Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A h
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerab
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber
Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acron
The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s
OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that al
Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thro
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse
OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discou
The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross
The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val
The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a
The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions
The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in
The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i
The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in
The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in al
The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve
The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers
PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting
An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved.
The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘woowho
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Heade
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation o
Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started