57,566 vulnerabilities published in 2026
HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica
Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify
A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the fil
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file lib
A vulnerability has been found in jarikomppa soloud up to 20200207. Impacted is the function drwav_read_pcm_frames_s16__
A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected eleme
A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the fun
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the c
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the back
A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/
A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. Affecte
HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or
OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symb
1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfS
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypa
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A docu
A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdo
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traver
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnera
A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/o
A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe
An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son
A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the f
A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects s
A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file
A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of th
A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unkno
A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unk
A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function
A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the
A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Re
A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/icon
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create f
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records.
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI esca
October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started