57,566 vulnerabilities published in 2026
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to
StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type
OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms
In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: k3: set hdma clock as critical HDMA
In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue
In the Linux kernel, the following vulnerability has been resolved: xfs: propagate errors from xfs_rtginode_load xfs_r
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fails
FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/s
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Pa
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa
Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 thr
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on th
In the Linux kernel, the following vulnerability has been resolved: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability
In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden daemon p
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if kvm_translate_vncr()
In the Linux kernel, the following vulnerability has been resolved: libbpf: Reject non-exclusive metadata maps in the s
In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folios in
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fai
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL state
RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-exi
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails
In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege
In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Objec
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Man
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem
Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started