57,566 vulnerabilities published in 2026
Tanium addressed an improper access controls vulnerability in Patch.
Tanium addressed an improper access controls vulnerability in Deploy.
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an improper access controls vulnerability in Reputation.
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the
The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an a
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below th
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administrat
The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the fil
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow
A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publi
A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the f
A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impact
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the fi
A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability i
A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discov
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could in
SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, res
Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker w
Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages),
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks
The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability
The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data du
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 1
GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8
Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform U
A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permis
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory.
An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view
The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creati
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started