57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer
In the Linux kernel, the following vulnerability has been resolved: drm/shmem_helper: Check VMA boundaries for PMD mapp
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol acc
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/w
In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C:
Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature pol
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr ent
In the Linux kernel, the following vulnerability has been resolved: ntfs3: fix out-of-bounds read in decompress_lznt d
In the Linux kernel, the following vulnerability has been resolved: drm/xe/userptr: Hold notifier_lock for write on inj
In the Linux kernel, the following vulnerability has been resolved: veth: fix NAPI leak in XDP enable error path Durin
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix potential UAF in aa_replace_profiles
In the Linux kernel, the following vulnerability has been resolved: char: tlclk: fix use-after-free in tlclk_cleanup()
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Serialize readq reset state with q-
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix OOB in scmi_power_name_get(
In the Linux kernel, the following vulnerability has been resolved: hfsplus: Add a sanity check for btree node size Sy
In the Linux kernel, the following vulnerability has been resolved: ufs: core: tracing: Do not dereference pointers in
In the Linux kernel, the following vulnerability has been resolved: driver core: use READ_ONCE() for dev->driver in dev
In the Linux kernel, the following vulnerability has been resolved: i2c: amd-mp2: Unregister callback on adapter add fa
In the Linux kernel, the following vulnerability has been resolved: riscv/mm: use physical alignment for vmemmap_start_
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Fix reading the minimum alarm volt
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for bo
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix guest_memory_dirty bitfield clobber
In the Linux kernel, the following vulnerability has been resolved: can: softing: fw_parse(): validate firmware record
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification wi
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix undersized format-check buffer fmt_
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd
In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t an
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode.
Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-o
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the fil
Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection
Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: f
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and
Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0,
Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to
Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element upda
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the L
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS ce
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.
A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the
Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rend
Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possibl
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started