57,566 vulnerabilities published in 2026
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapj
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC)
WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attack
WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f
Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, s
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox prefere
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25
WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers
WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers
WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated at
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include a
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv
A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially cr
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes
mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially s
decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause alloc
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker co
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a re
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sen
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on
pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started