57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: selinux: allow multiple opens of /sys/fs/selinux/po
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: os_dep: avoid NULL pointer dere
In the Linux kernel, the following vulnerability has been resolved: media: renesas: vsp1: Fix NULL pointer deref on mod
In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: Set vma_flags in vb2_dma_sg_mmap
In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix error pointer dereference I
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject empty multisync extension to preven
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i
Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying i
In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_
In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture remov
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locall
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an a
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informati
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memor
Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially lead
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could r
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could r
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead t
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnera
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon
Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks
Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded outp
Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows at
Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulner
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.1
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started