57,566 vulnerabilities published in 2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote
Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate
Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS co
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t
Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin u
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
Memory corruption in diagnostic services due to absence of input validation
Memory corruption in windows drivers while sending incorrect trusted application request
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
Memory Corruption when sending random number generator command with insufficient output buffer size.
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller fi
During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-
Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne
Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker
Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An att
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb c
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4,
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized
In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported v
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op
Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u4
Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started