57,566 vulnerabilities published in 2026
YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read l
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect avai
FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administra
IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text bloc
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of m
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a
stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7
The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure wi
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonom
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5
This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS
IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_p
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive a
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Ha
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attacke
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used b
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (da
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The h
Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A mali
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step tem
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attack
bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associat
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started