57,566 vulnerabilities published in 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic
CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i
The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and
The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin
The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary
Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help
SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain se
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w
SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the funct
The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the Woo
A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAu
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code o
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the fil
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started