57,566 vulnerabilities published in 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Contributor Broken Access Control in uListing <= 2.2.0 versions.
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_
Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserN
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg
Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.t
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.E
Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to dow
IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec
An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers f
A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to
The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started