57,566 vulnerabilities published in 2026
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
Memory Corruption when sending random number generator command with insufficient output buffer size.
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller fi
During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-
Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne
Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker
Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An att
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb c
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4,
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized
In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported v
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u4
Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Da
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the
Memory Corruption when processing registry values with incorrect types using a direct query method.
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed
Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started