57,566 vulnerabilities published in 2026
Vulnerability in Oracle Fusion Middleware (component: Dynamic Monitoring Service). Supported versions that are affected
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page,
WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim ope
An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution wh
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `saf
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitr
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` paramet
OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allo
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direc
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scop
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths
OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previ
OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to
A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allo
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersona
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF t
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection
A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unk
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() fu
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionali
A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph
The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unau
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The
OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th
OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restri
OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure become
OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared ga
Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request F
Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can per
Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated a
LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the para
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled
A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a
Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function s
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started