57,566 vulnerabilities published in 2026
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based adm
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability
A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-
Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /ad
A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file
A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the fi
A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the a
A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknow
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to acc
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit
The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve
The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forger
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build confi
zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets
A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 1
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on th
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.
ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, Rep
HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of t
A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi
Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`
A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of
A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated att
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the fi
A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such
Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated,
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log f
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configur
The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started