57,566 vulnerabilities published in 2026
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tamperin
jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlle
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications
An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt
An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery
Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation).
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affe
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported v
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_i
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on A
In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Treat memslot binding offset+size
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to guard ke
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko
In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until probe s
In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read erro
In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanu
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1
A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 2
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafte
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted k
Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac
The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Ser
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started