57,566 vulnerabilities published in 2026
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci
The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th
The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory wit
The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted
The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effect
A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filen
A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-
A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when uti
A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during
A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:]
A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when usin
OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass
A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.t
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gid
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.
An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an intege
A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::se
A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit:
A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the f
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the
A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /
A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file sr
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit
Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of t
This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app ma
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPa
The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability
Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applic
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the U
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UF
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists i
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex
A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/t
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to r
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v
NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz
A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file sr
A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/
A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER
A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_sec
A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started