57,566 vulnerabilities published in 2026
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul
Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Con
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redir
Missing Authorization vulnerability in baqend Speed Kit baqend allows Exploiting Incorrectly Configured Access Control S
Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slidesho
Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured
Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollmen
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completio
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2
OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allo
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up
ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a
Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's a
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacke
Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access info
SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensiti
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Fir
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. Th
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized m
The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i
Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authenticatio
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially l
An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without
Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions thr
Certain error messages returned by the application expose internal system details that should not be visible to end user
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to e
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listin
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to
The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu
The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D
The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2
The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.
The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. Thi
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started