57,566 vulnerabilities published in 2026
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string
In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servic
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local informati
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
In display, there is a possible information disclosure due to an integer overflow. This could lead to local information
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servi
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a
A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getCo
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos
The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver
xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W
Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo
A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information d
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se
Local File Inclusion via file:// URI in Migration Restore
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls
The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi
The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripti
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 u
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrol
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and be
A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn o
The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version
A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validate
CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started