57,566 vulnerabilities published in 2026
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach
Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg
Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect a
Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may ex
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCl
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulne
AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to
OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escala
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote
Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate
Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS co
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t
Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin u
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
Memory corruption in diagnostic services due to absence of input validation
Memory corruption in windows drivers while sending incorrect trusted application request
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started