57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access
In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds c
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs before
In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission mask fo
In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent out-of-bounds read in glob matchin
In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to the S
In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to the ppe
In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT ino
In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before rea
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before fi
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-term
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and M
In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp stat
In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error path
In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_event_g
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, mac
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS So
A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix OOB read in drm_parse_tiled_block()
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and e
wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlle
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability wh
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colle
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remot
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started