57,566 vulnerabilities published in 2026
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to vers
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16
Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead
Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in it
pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when run
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HT
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca
CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite pr
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application dis
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application dis
A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a lo
A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticat
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and
Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionali
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden
In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This
In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel infor
HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter)
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exi
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform che
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell co
IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code
Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking
In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local es
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Z
Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 s
OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect
A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rej
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() functio
H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in t
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content bein
Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applicati
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside th
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent ti
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started