57,566 vulnerabilities published in 2026
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent
Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify
Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a
An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l
An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c
Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary
An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi
A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p
Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini
Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc
Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp
Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf
Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr
An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memo
Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf
Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat
SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of t
Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenti
* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually
An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prio
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame
Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor
Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has
Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all
FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize dat
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authent
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe
The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input.
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An
The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started