57,566 vulnerabilities published in 2026
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host c
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRe
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via
The application does not impose strict enough restrictions on directory access permissions, posing a risk that other mal
Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM becaus
Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attac
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed
ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a tem
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attack
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attac
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocatio
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function i
Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit
A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expos
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic
A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could all
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder f
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5,
Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. Use
Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the rec
The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver setti
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot
MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started