57,566 vulnerabilities published in 2026
The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, an
The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1
Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that all
hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to injec
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allo
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated thro
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers w
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Rea
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secret
A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allow
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Ite
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers wi
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller,
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp a
Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote
Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private reposi
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a den
NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/ag
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started