57,566 vulnerabilities published in 2026
A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote
TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods i
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Implement a crw lock Unlike the cha
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Selectively expand io_mutex The io_
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The init
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring pack
Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote atta
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticat
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attac
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected p
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary c
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows networ
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on th
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/s
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management inte
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HT
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated atta
Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins
In the Linux kernel, the following vulnerability has been resolved: batman-adv: gw: acquire ethernet header only after
In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for numbe
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix iommu domain lifetime race durin
In the Linux kernel, the following vulnerability has been resolved: iommufd: Take dma_resv lock before dma_buf_unpin()
In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from short trigger BA f
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove_refc
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix u16 truncation of restart-area length che
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: give the socket its own sco_conn re
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/l
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params befo
In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becom
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPac
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authen
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to impro
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first throu
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started