57,566 vulnerabilities published in 2026
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pa
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. D
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that
HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de
Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte
In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption on a failed
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may al
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix VF bringup affecting PF promiscuo
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts
sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vuln
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive informatio
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Fix out of bounds check on CCW array
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an at
A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubern
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attac
In the Linux kernel, the following vulnerability has been resolved: hfs: fix potential use after free in hfs_correct_ne
In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noex
An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder wit
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i
In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege
Memory corruption while deinitializing a HDCP session.
Memory corruption while processing a video session to set video parameters.
Memory corruption while processing a secure logging command in the trusted application.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started