57,566 vulnerabilities published in 2026
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerabilit
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al
A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leadin
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in
llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper w
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern
In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWid
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the
A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading maliciou
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver
A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to d
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started