57,566 vulnerabilities published in 2026
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke Ca
The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver
Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper en
openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_pat
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comme
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arb
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component doe
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro
IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio
IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ
coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq
Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affect
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph
The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given
Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started