57,566 vulnerabilities published in 2026
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discov
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina
Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain pot
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and th
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of ser
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerabilit
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al
A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leadin
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in
llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper w
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern
In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWid
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the
A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading maliciou
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver
A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started