57,566 vulnerabilities published in 2026
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM
X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerab
A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the
A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /chec
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the fi
A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unkno
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB
OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to e
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompt
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to mess
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement f
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCod
Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change admini
A vulnerability has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /che
A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown f
The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul
Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in a
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated S
A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode
The Material Master application does not enforce authorization checks for authenticated users when executing reports, re
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker c
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to u
A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application us
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log tru
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to p
Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cr
The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8.
Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf
Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A
Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started