57,566 vulnerabilities published in 2026
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose i
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to applicat
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacke
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information lo
Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application
Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could
Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authoriza
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes
In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported version
Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected vers
The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions
The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By cr
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix leak of kobject name for sub-group space
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix NULL pointer dereference in netfs_unbuff
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix kernel BUG in netfs_limit_iter() for ITE
In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix regmap init error hand
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix leaking event log memory Duri
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix memory leak when a wq is reset
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix crash when the event log is di
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: avoid use of half-online-committed c
In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with proper error handling in
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts->nr in repeat_call_f
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts->nr before accessing
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix param_ctx leak on damon_sysfs_n
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check if ext_caps is valid in BL s
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix drm_edid leak in amdgpu_dm [W
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent immediate PASID reuse case PAS
In the Linux kernel, the following vulnerability has been resolved: writeback: don't block sync for filesystems with no
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started