57,566 vulnerabilities published in 2026
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Matter
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the D
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead
Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows u
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any
TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t
Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller
Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framewo
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_label
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exceptio
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip add
@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,
SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started