Products: 35
    Vulnerabilities: 5
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-42349

    Clerk: Authorization bypass when combining organization, billing, or reverification checks

    Last Modified: Jun 01, 2026
    Published: May 11, 2026

    CVE-2026-41248

    Official Clerk JavaScript SDKs: Middleware-based route protection bypass

    Last Modified: Apr 27, 2026
    Published: Apr 24, 2026

    CVE-2026-34076

    Clerk JavaScript: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host

    Last Modified: Apr 03, 2026
    Published: Apr 01, 2026

    CVE-2025-63700

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Last Modified: Dec 23, 2025
    Published: Nov 20, 2025

    CVE-2024-22206

    @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

    Last Modified: Nov 21, 2024
    Published: Jan 12, 2024
    Items Per Page