57,566 vulnerabilities published in 2026
A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delst
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate
IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or sessi
A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the li
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library st
A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the l
A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file s
A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/deco
A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown f
A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the compone
A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. Thi
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the medi
prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media genera
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas
Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the
A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packa
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtil
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember
A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the
A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /
A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. P
CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administra
A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file up
A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php
A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of
A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file
Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Im
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/custo
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admi
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f
In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv
Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-
The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela
Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configu
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Con
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started