57,566 vulnerabilities published in 2026
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attac
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, t
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration
A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affe
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings access
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMA
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerabilit
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitr
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10.
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy o
MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/vie
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa
The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did n
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer
Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (r
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged a
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthoriz
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap bu
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sens
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started