57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/q54sj108a2) fix stack overflow in deb
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: clear walk_control on inactive conte
In the Linux kernel, the following vulnerability has been resolved: ceph: add a bunch of missing ceph_path_info initial
In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: fix use-after-free in ISR durin
In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in off
In the Linux kernel, the following vulnerability has been resolved: rust_binder: check ownership before using vma When
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: fix use-after-free on linked stream runt
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Remove redundant css_put() in scx_cgroup
In the Linux kernel, the following vulnerability has been resolved: net/mana: Null service_wq on setup error to prevent
In the Linux kernel, the following vulnerability has been resolved: iavf: fix PTP use-after-free during reset Commit 7
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix for duplicate device in n
In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave(
In the Linux kernel, the following vulnerability has been resolved: serial: caif: hold tty->link reference in ldisc_ope
In the Linux kernel, the following vulnerability has been resolved: spi: rockchip-sfc: Fix double-free in remove() call
In the Linux kernel, the following vulnerability has been resolved: spi: amlogic: spifc-a4: Fix DMA mapping error handl
pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could
Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when page
Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vuln
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that l
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9
libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas
A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user
A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t
A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is v
A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications con
Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi
Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applicati
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started