57,566 vulnerabilities published in 2026
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to exec
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could resu
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too
An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client valid
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package).
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Mos
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r
rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attack
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code loca
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization
PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which lo
In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length
In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path
In the Linux kernel, the following vulnerability has been resolved: f2fs: bound i_inline_xattr_size for non-inline-xatt
In the Linux kernel, the following vulnerability has been resolved: f2fs: validate orphan inode entry count f2fs_recov
In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes
In the Linux kernel, the following vulnerability has been resolved: bpf: Propagate error from visit_tailcall_insn Comm
In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430
In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_p
In the Linux kernel, the following vulnerability has been resolved: memfd: deny writeable mappings when implying SEAL_W
In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - use cached peer pointer in ovpn_tcp_clo
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Validate framework notification
In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If
In the Linux kernel, the following vulnerability has been resolved: iommupt: Check for missing PAGE_SIZE in the pgsize_
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i
A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common M
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started