2026
57,566 vulnerabilities published in 2026
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user inp
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack o
Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/
Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/com
Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.ph
Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.
TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft W
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected de
In the Linux kernel, the following vulnerability has been resolved: hfsplus: Verify inode mode when loading from disk
In the Linux kernel, the following vulnerability has been resolved: inet: frags: flush pending skbs in fqdir_pre_exit()
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix return value of f2fs_recover_fsync_data()
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix kernel BUG in ocfs2_find_victim_chain s
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid updating compression context dur
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching
In the Linux kernel, the following vulnerability has been resolved: net/hsr: fix NULL pointer dereference in prp_get_un
In the Linux kernel, the following vulnerability has been resolved: Input: ti_am335x_tsc - fix off-by-one error in wire
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't log conflicting inode if it's a dir mo
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid unregistering PSP twice PSP is un
In the Linux kernel, the following vulnerability has been resolved: sched/deadline: only set free_cpus for online runqu
In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free in delayed wo
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-mixer: us16x08: validate meter packet ind
In the Linux kernel, the following vulnerability has been resolved: xfs: fix a UAF problem in xattr repair The xchk_se
In the Linux kernel, the following vulnerability has been resolved: ksmbd: skip lock-range check on equal size to avoid
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix memory leak in nr_sendmsg() syzbot rep
In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on c
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix double unregister of HCA_PORTS compon
In the Linux kernel, the following vulnerability has been resolved: fuse: missing copy_finish in fuse-over-io-uring arg
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid updating zero-sized extent in ex
In the Linux kernel, the following vulnerability has been resolved: char: applicom: fix NULL pointer dereference in ac_
In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: Check event before enable to avoid GP
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Limit num_syncs to prevent oversized alloca
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_ishtp: Fix UAF after unbin
In the Linux kernel, the following vulnerability has been resolved: block: fix race between wbt_enable_default and IO s
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix ipv4 null-ptr-deref in route error path
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix filename leak in __io_openat_prep()
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string paramet
In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_ino
In the Linux kernel, the following vulnerability has been resolved: fuse: fix readahead reclaim deadlock Commit e26ee4
In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to a
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock As Jiaming Z
In the Linux kernel, the following vulnerability has been resolved: ntfs: set dummy blocksize to read boot_block when m
In the Linux kernel, the following vulnerability has been resolved: f2fs: invalidate dentry cache on failed whiteout cr
Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability,
@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assi
Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started