57,566 vulnerabilities published in 2026
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & L
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain
An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU dispr
An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal ha
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression st
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs w
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce
Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoo
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing una
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset e
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi
Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling be
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation che
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali
Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks
WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger
The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's
The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,
The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C
The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi
Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. W
The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para
The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at
The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name'
The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel
The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig
The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions
The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in
The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all
The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version
The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started