57,566 vulnerabilities published in 2026
Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption heade
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could all
This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads
Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent
In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4
In the Linux kernel, the following vulnerability has been resolved: Revert "f2fs: block cache/dio write during f2fs_ena
In the Linux kernel, the following vulnerability has been resolved: platform/x86: classmate-laptop: Add missing NULL po
In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low pr
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src
OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget
Sensitive information disclosure due to improper configuration of a headless browser. The following products are affecte
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink t
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to
DNG SDK versions 1.7.1 2471 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Val
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started