57,566 vulnerabilities published in 2026
IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio
IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ
coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq
Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affect
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph
The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given
Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us
Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User
IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network se
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a sp
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards call
Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may a
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71,
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-c
Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging so
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to ob
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other toke
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started