57,566 vulnerabilities published in 2026
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that a
OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b
OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox conf
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
Denial of service due to insufficient input validation in authentication logging. The following products are affected: A
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version
The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo
EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive
AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor
Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensi
Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary direct
Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by
An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints.
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDN
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server
GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary wi
GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a38
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i
The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc
The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1
express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t
UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /sessio
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7,
Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_r
Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combine
Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started