57,566 vulnerabilities published in 2026
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSd
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH bac
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 conn
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domai
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin
Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthentica
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingCon
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStor
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P
OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-e
OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC u
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Exte
OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON
OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that
OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allow
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all adm
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NT
The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0.
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resource
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies,
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart construc
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumerat
Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v
A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the
A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file tra
A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file bac
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unkn
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the fil
A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile o
A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A l
A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul
A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess
OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploa
A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started