57,566 vulnerabilities published in 2026
When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature
The application re-enters the document structure via field processing and deletes the current page, and then continues u
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object
After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi
The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio
There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina
Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install
A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco
PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a
Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls.
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte
Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func
Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an
On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a secu
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elev
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started