57,566 vulnerabilities published in 2026
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us
Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User
IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network se
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a sp
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards call
Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may a
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71,
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-c
Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging so
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to ob
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other toke
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn
Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr
The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of th
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are aff
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1
There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop appli
An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerab
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the in
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the
Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model incl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started