57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: PM: hibernate: Fix crash when freeing invalid crypt
In the Linux kernel, the following vulnerability has been resolved: net/ena: fix missing lock when update devlink param
In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix device mismatch in devm_kzalloc/dev
In the Linux kernel, the following vulnerability has been resolved: libceph: make calc_target() set t->paused, not just
In the Linux kernel, the following vulnerability has been resolved: udp: call skb_orphan() before skb_attempt_defer_fre
In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qusb2: Fix NULL pointer dereference on ea
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock in wait_current_trans() due to
In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix regmap max_register T
In the Linux kernel, the following vulnerability has been resolved: phy: stm32-usphyc: Fix off by one in probe() The "
In the Linux kernel, the following vulnerability has been resolved: w1: therm: Fix off-by-one buffer overflow in alarms
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors
In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91-sama5d2_adc: Fix potential use-after
In the Linux kernel, the following vulnerability has been resolved: drm/panel-simple: fix connector type for DataImage
In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix a deadlock when returning a delegation du
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix drm panic null pointer when driver
In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not over-allocate ftrace memory The pg_
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a deadlock involving nfs_release_folio()
In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming wit
In the Linux kernel, the following vulnerability has been resolved: i2c: riic: Move suspend handling to NOIRQ phase Co
In the Linux kernel, the following vulnerability has been resolved: uacce: implement mremap in uacce_vm_ops to return -
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Coalesce only linear skb vsock/virti
In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): fix URB
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Sanitize payload size to prevent mem
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-ex
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P
Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated
Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vuln
In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated ar
The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displ
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP
Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/
Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/Con
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows
DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an att
captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and
The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. Th
Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping
Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter valu
Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o
Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds
A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t
Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec
Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could
Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively
A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK
Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever
Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent
Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started