57,566 vulnerabilities published in 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of t
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 un
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf
A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytdlp_download of the file sr
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deser
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes di
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape th
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include f
libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10
Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Transient DOS while parsing video packets received from the video firmware.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a ses
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke
An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functi
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field
Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a pa
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with syste
Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access s
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a
Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bun
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table Wh
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Limit num_syncs to prevent oversized all
In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allo
In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_devic
In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The re
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Avoid NULL pointer deref for evicted BOs
In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix leaking the multicast GID table refere
In the Linux kernel, the following vulnerability has been resolved: iavf: fix off-by-one issues in iavf_config_rss_reg(
In the Linux kernel, the following vulnerability has been resolved: mptcp: fallback earlier on simult connection Syzka
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use Th
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Check for the presence of LS_NLA_TYPE_DG
In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error rou
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started