57,566 vulnerabilities published in 2026
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restriction
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless clie
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does n
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software an
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secur
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acr
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Prot
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyb
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Prot
A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown funct
Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category
The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr
Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers t
The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl
The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti
The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2
The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi
The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve Wire
A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functi
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown f
A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This ma
A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the fil
A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function inp
Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se
Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but
The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which coul
Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks co
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access
Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token e
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w
LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRep
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started