57,566 vulnerabilities published in 2026
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem
A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this is
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through
OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag
@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file a
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of
A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a
Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Se
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T
Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl
The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store th
djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started