57,566 vulnerabilities published in 2026
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >=
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class
In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_rang
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-size
In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE
In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating tw
In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord
In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a
In the Linux kernel, the following vulnerability has been resolved: xfs: get rid of the xchk_xfile_*_descr calls The x
In the Linux kernel, the following vulnerability has been resolved: net: gro: fix outer network offset The udp GRO com
In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before que
In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on ca
In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failur
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nvme_f
In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix page array leak d9f595b9a65e ("
In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: Check if ASPM is enabled from PCIe
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer in {rea
In the Linux kernel, the following vulnerability has been resolved: fbdev: rivafb: fix divide error in nv3_arb() A use
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w
An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when
OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers
In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functi
In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in ip
A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream ca
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer
Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c
WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/
OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypas
The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me
Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the applica
SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local atta
jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to
PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by
RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash the ap
SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arb
jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by su
GSearch 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by input
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started