57,566 vulnerabilities published in 2026
OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessi
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSF
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an a
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 al
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injec
Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize man
Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-pr
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where use
Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the
Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the d
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerab
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bo
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could cr
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-base
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due t
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a de
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insu
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
Memory corruption while handling buffer mapping operations in the cryptographic driver.
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vul
A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality o
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the f
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execut
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
Tanium addressed a documentation issue in Engage.
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists
Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Acce
A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the
Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components
Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements use
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started