57,566 vulnerabilities published in 2026
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea
Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @c
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints
In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoint
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to int
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middle
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows
Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affec
OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued a
OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade
An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset f
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica
In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi
In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->t
In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from den
In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-termina
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Sessi
OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not ade
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, a
In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in p
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, t
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical v
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior
auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is pas
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achie
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagn
A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerab
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterp
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started