57,566 vulnerabilities published in 2026
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the networ
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause un
Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke
Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat
Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver
Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may
Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: Use
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Rin
Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adve
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ri
Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a den
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirec
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s
sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, impl
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element res
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an inp
Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder()
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, eve
django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerabl
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk usin
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec
Improper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigg
The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.a
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalc
Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat
A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL c
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticate
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbo
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query paramet
MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote r
MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started