57,566 vulnerabilities published in 2026
Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predict
Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Pr
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell module
Memory corruption while processing a config call from userspace.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Memory corruption while parsing clock configuration data for a specific hardware type.
Memory corruption while performing sensor register read operations.
Memory corruption while accessing a synchronization object during concurrent operations.
Memory corruption while handling sensor utility operations.
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to eleva
In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a
NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, Psy
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri
Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) regi
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permi
Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 throug
Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR
Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolki
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584
Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow
Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Appli
Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an
Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) S
Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applica
Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an a
The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on be
OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetD
Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authenticatio
An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could a
An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 ma
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerabi
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerabilit
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started