57,566 vulnerabilities published in 2026
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from th
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing dirty page tracking in {pte,
In the Linux kernel, the following vulnerability has been resolved: ieee802154: admin-gate legacy LLSEC dump operations
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Reject firmware log with size smaller t
In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice ha
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device removal
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-PP control to all d
In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI if the vCPU has sin
In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range traffic classes in Qo
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writeback error handling Fix the error
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator core
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_version in pmbus_data
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Validate written enum value in ge_put_e
In the Linux kernel, the following vulnerability has been resolved: ice: fix FDIR CTRL VSI resource leak in ice_reset_a
In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and barrier reference
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix uninitialised pointer passed to audit
In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build before no_new_privs tes
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent potential lcn remains uninitializ
In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Validate written enum v
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: hdac_hdmi: Validate written enum valu
In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a cluster
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps as inner maps in map-in-
In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: reject a flag character as the field d
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validate hashtable support
In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_key_chu
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processi
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could l
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system
Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/serve
Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authe
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior t
SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/u
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability
ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where
ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTI
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, Dire
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started