57,566 vulnerabilities published in 2026
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows D
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all
OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c
Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to befor
TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\N
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-chann
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt pa
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by th
A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of
HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise wh
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in
Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or
PRSD detection denial of service
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_commo
OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumv
OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows leg
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in l
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_de
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagege
A vulnerability was detected in 666ghj MiroFish up to 0.1.2. The impacted element is an unknown function of the file /co
A vulnerability was determined in code-projects Chat System 1.0. Affected is an unknown function of the file update_user
The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP
OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use ea
OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xx
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing character
A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_
A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi
A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev
A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unk
A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verify
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v
HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatc
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted ove
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packag
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed direct
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started