57,566 vulnerabilities published in 2026
Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al
Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le
A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially
Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged atta
Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m
Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a
Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI
Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting
Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot
Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po
CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintende
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclo
A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary
Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to
Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially result
Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,
A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged use
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® softwa
manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability th
Reflected Cross-Site Scripting (XSS) vulnerability in the Wix web application, where the endpoint ' https://manage.wix.c
Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially re
Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Gl
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr
Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kuberne
A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to t
Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and applicati
Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones,
Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces
Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handl
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoo
HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the applica
Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vu
beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: handle changing device dma map requiremen
In the Linux kernel, the following vulnerability has been resolved: platform/x86: toshiba_haps: Fix memory leaks in add
In the Linux kernel, the following vulnerability has been resolved: mm, shmem: prevent infinite loop on truncate race
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fixup hang in nvmet_tcp_listen_data_read
In the Linux kernel, the following vulnerability has been resolved: btrfs: sync read disk super and set block size Whe
In the Linux kernel, the following vulnerability has been resolved: spi: tegra: Fix a memory leak in tegra_slink_probe(
In the Linux kernel, the following vulnerability has been resolved: cgroup/dmem: fix NULL pointer dereference when sett
The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a r
The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires
The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing onl
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) d
SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a prev
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started