57,566 vulnerabilities published in 2026
The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized
Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct
The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF)
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Confi
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessi
Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering she
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of
Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker
Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker t
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network
The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ
Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when crea
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint all
The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability
Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via
Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the Del
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lea
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass
The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca
The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl
The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c
The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged
Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory
Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated
A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to
Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by trickin
Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user
A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the fi
A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unkno
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnera
A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown functio
A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown func
A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the fil
A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown func
A vulnerability has been found in code-projects Employee Management System 1.0. Affected by this issue is some unknown f
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the
Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to del
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of
A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started