57,566 vulnerabilities published in 2026
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed c
The vulnerability allows the unauthorised generation of physical access QR codes due to the use of hard-coded credential
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged n
An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Servi
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause
In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: fix NULL pointer dereference in ar_
In the Linux kernel, the following vulnerability has been resolved: l2tp: fix tunnel and session refcount leak on seq_f
In the Linux kernel, the following vulnerability has been resolved: regmap: sdw-mbq: don't call an unset readable_reg c
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix TOCTOU NULL deref on a->got
In the Linux kernel, the following vulnerability has been resolved: rseq: Prevent hard lockup on granted time slice ext
In the Linux kernel, the following vulnerability has been resolved: scsi: core: pair EH runtime PM get and put shost->
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python pr
In the Linux kernel, the following vulnerability has been resolved: optee: ffa: Add NULL check in optee_ffa_lend_protme
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Refresh copier IPC payloa
In the Linux kernel, the following vulnerability has been resolved: xfs: don't swallow dquot recovery verification erro
In the Linux kernel, the following vulnerability has been resolved: xfs: fix another iunlink infinite loop bug in onlin
In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a null sc->sa.agi_bp
In the Linux kernel, the following vulnerability has been resolved: xfs: fix ilock leak on error in xfs_dq_get_next_id
In the Linux kernel, the following vulnerability has been resolved: xfs: don't double-lock when deleting a self-referen
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: disallow multiple FENCE chunks in one s
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference in am
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Pad trailing CCA or EP11 message with
In the Linux kernel, the following vulnerability has been resolved: gpio: ml-ioh: use raw_spinlock_t for the register l
In the Linux kernel, the following vulnerability has been resolved: gpio: sloppy-logic-analyzer: fix use-after-free via
In the Linux kernel, the following vulnerability has been resolved: gve: fix NULL dereference due to missing ptp adjfin
In the Linux kernel, the following vulnerability has been resolved: Input: hynitron_cstxxx - validate touch count and f
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - propagate F54 worker errors
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: papr-phy-attest - validate cmd.len
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - validate input packet lengths ifor
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: skip zero-sized firmware sections pan
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the S
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary s
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf
Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d
Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, pass
CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communicatio
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versi
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b
A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms
stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP co
Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional a
Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access
The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directl
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arb
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql para
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries admin
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started