57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: mm: fix __vm_normal_page() to handle missing suppor
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d
Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an
In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free i
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_
In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid
DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the e
Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap cor
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manage
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod
Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported v
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easil
Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is
Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Di
Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). Th
Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous). Supported
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: B
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: P
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attack
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) a
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In
When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started