57,566 vulnerabilities published in 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c
NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequa
In the Linux kernel, the following vulnerability has been resolved: mm/slab: return NULL early from kmalloc_nolock() in
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_rwsem
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_sub_gro
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super(
In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cach
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel al
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (ui
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticate
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump direc
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr
api-gateway container running with root privilege would allow an attacker to escape the container and access host system
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to loc
In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local e
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started