57,566 vulnerabilities published in 2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can cra
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to mem
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to mem
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash t
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unb
A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Ba
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific condit
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators t
ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to au
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker t
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privileg
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to inst
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >=
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class
In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_rang
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-size
In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE
In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating tw
In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord
In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a
In the Linux kernel, the following vulnerability has been resolved: xfs: get rid of the xchk_xfile_*_descr calls The x
In the Linux kernel, the following vulnerability has been resolved: net: gro: fix outer network offset The udp GRO com
In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic
In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before que
In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on ca
In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failur
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nvme_f
In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix page array leak d9f595b9a65e ("
In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: Check if ASPM is enabled from PCIe
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer in {rea
In the Linux kernel, the following vulnerability has been resolved: fbdev: rivafb: fix divide error in nv3_arb() A use
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started