57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Use unsigned int for ndp_index
In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: properly kill rcv_urb on error in
In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: check ibuf_len against rxbuf_len
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write on Type II inbound U
In the Linux kernel, the following vulnerability has been resolved: Input: evdev - sanitize event type index when fetch
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits Whe
In the Linux kernel, the following vulnerability has been resolved: rqspinlock: Reset tail when preserving queue on dea
In the Linux kernel, the following vulnerability has been resolved: net: prestera: validate firmware header length pre
In the Linux kernel, the following vulnerability has been resolved: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD pa
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix BQL reset on SQ re-activation mlx5e
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in exec_queue_set_hang_repl
In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device re
In the Linux kernel, the following vulnerability has been resolved: xsk: clear metadata pointer when no timestamp is re
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix locally exploitable BUG_ON in am
In the Linux kernel, the following vulnerability has been resolved: devlink: fix net namespace reference leak in reload
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write()
In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_b
In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in sn
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check for tg ops in dce110_set_avm
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vuln
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Build
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authentic
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth rang
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An atta
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 al
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sens
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 all
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of
RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint p
RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated rem
RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked
Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlle
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim
RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The
RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents ar
RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Locati
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an a
Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackdu
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en
RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocu
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net
The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5
Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injectio
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative acces
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started