57,566 vulnerabilities published in 2026
OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce
OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration in
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor
MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original
A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulne
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option d
LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versio
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint tha
ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php
SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobpor
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to fi
OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrar
Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data sup
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r
NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me
OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s
OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local f
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allow
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control S
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor
Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows aut
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to befo
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows atta
LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized
A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started