57,566 vulnerabilities published in 2026
Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary Angula
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it
Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi
EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat
EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful ex
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaSc
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit
There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which
Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke Ca
The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver
Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper en
openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_pat
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comme
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arb
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component doe
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro
IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started