57,566 vulnerabilities published in 2026
Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint th
Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry pat
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, al
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil
In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Qu
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Se
Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predict
Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Pr
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell module
Memory corruption while processing a config call from userspace.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Memory corruption while parsing clock configuration data for a specific hardware type.
Memory corruption while performing sensor register read operations.
Memory corruption while accessing a synchronization object during concurrent operations.
Memory corruption while handling sensor utility operations.
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to eleva
In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a
NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, Psy
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri
Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) regi
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permi
Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 throug
Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR
Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolki
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584
Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started