57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate data l
In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when state
In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_queue ordered In a
In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_pr
In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cancel the preallocation
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrpc_recvmsg() Fix a
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_challenge() Fix rxgk_
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto the pen
In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with s
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up t
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the outp
In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortci
In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit pat
In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_rx()
In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link grou
In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error cleanup If an erro
In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-frag skb on DMA map
In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segmen
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delt
In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Ho
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basi
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the functio
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl a
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability i
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code t
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles fr
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugi
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silent
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based)
An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted reque
An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started