57,566 vulnerabilities published in 2026
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the
SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the w
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contai
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to
A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provid
A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it
An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predict
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition
A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweig
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a l
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach
Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg
Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect a
Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may ex
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCl
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulne
AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to
OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escala
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started