57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs to t
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of returning
In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlock_o
In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold hdev->lock for hci_conn_p
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: extend conn_hash lookup critic
In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in a
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serv
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code
A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by expl
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extensi
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-a
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerabili
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker t
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execut
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to ex
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code o
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute co
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started