57,566 vulnerabilities published in 2026
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attack
In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in
Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability.
WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereb
Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure wor
BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulner
In the Linux kernel, the following vulnerability has been resolved: ALSA: ac97: fix a double free in snd_ac97_controlle
A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of t
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Lin
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequ
In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under specul
In the Linux kernel, the following vulnerability has been resolved: net: cpsw: Execute ndo_set_rx_mode callback in a wo
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: add bounds check for if_id in IRQ han
In the Linux kernel, the following vulnerability has been resolved: cgroup/dmem: avoid pool UAF An UAF issue was obser
A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in
A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown functi
A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functional
Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It ca
In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local esc
A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function in the library cryptbase
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM P
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Associatio
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Associatio
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized att
Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduc
Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL inject
A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PR
A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextSha
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in devmap on PREEMPT_RT On PREEMPT_R
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C
A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown func
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in t
In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_c
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started