57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: net: mana: Skip redundant detach on already-detache
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Use spin_lock_bh for hn_lock nvmet_
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Run queues for all non-SDEV_DEL devices
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix dma_vecs leak on p2p memory We don't
In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: add NULL check for idev in ipv6_hop_ioa
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in proc_show_fi
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in compare_guid
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait F
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: stop TX during firmware restart
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser
The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon
The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQ
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115
Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderb
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi
Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started