57,566 vulnerabilities published in 2026
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an ou
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys
LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execu
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0,
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0,
Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command inj
IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow
erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.jso
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7
A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, Fort
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI t
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret o
OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect p
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically all
Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permi
Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compro
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin
A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged fu
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerab
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2,
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported
Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in S
Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and
Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with
Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during lo
Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing
Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access duri
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. Wh
The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across file
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's ta
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address informati
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The
Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App
Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications
Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Appl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started