57,566 vulnerabilities published in 2026
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows,
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation le
ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbP
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs dur
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability.
The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is
An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java compo
The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client d
Memory Corruption when accessing buffers with invalid length during TA invocation.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and
Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.
Memory Corruption when accessing trusted execution environment without proper privilege check.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Memory Corruption when adding user-supplied data without checking available buffer space.
Memory Corruption when processing invalid user address with nonstandard buffer address.
Memory corruption while using alignments for memory allocation.
In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive director
In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due
In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previou
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. Thi
In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead
In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t
In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code.
In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due
In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This c
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to
OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack impo
iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.
The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tabl
Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid mapping wrong physical block for
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_write_end_io() As s
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid
A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a l
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started