57,566 vulnerabilities published in 2026
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/c
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read API
Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. The
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a
A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have cre
Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Boar
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the networ
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause un
Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke
Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat
Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver
Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may
Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: Use
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Rin
Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adve
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ri
Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a den
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirec
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s
sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, impl
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element res
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an inp
Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder()
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, eve
django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerabl
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk usin
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec
Improper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigg
The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.a
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalc
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started