57,566 vulnerabilities published in 2026
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi
Substance3D - Painter versions 11.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Sampler versions 5.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could resul
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)
Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result
PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers t
ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows loca
WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra
Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with
BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows lo
TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable fi
Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affe
In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc
In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_
In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_op
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Zero-initialize the eb.vma array in i
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix "UBSAN: shift-out-of-bounds error
In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before acc
NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T
MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service ex
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServ
Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authe
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious pro
DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that a
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalS
Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that
SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows loca
Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrar
TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem pri
Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code
Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code
iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attacke
Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with Lo
Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows loca
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local
Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows loc
Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that
WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attack
Delta Electronics DIAView has Command Injection vulnerability.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started