57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix possible deadlock between unlink and dio
In the Linux kernel, the following vulnerability has been resolved: arm64: mm: Handle invalid large leaf mappings corre
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate EaNameLength in smb2_get_ea() smb2
In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Only put the call ref if one was acquired r
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix use of wrong skb when comparing queued R
In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::deriv
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFin
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively wal
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buf
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea
In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challeng
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird
Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these b
CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the app
Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 cha
Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated rem
An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial o
A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read
An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0.
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive inf
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes
OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication bud
OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthentica
OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approva
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to pote
Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromise
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to exec
Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the rendere
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrect
Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file cre
TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname pa
An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) c
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started