57,566 vulnerabilities published in 2026
PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system file
Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration par
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attack
Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters th
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to
Nidesoft DVD Ripper 5.2.18 contains a local buffer overflow vulnerability in the License Code registration parameter tha
Port Forwarding Wizard 4.8.0 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary c
Socusoft Photo to Video Converter Professional 8.07 contains a local buffer overflow vulnerability in the 'Output Folder
FTPDummy 4.80 contains a local buffer overflow vulnerability in its preference file handling that allows attackers to ex
Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary co
RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to ex
Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by craf
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the 'Find Computer' feature that allows
Frigate 3.36.0.9 contains a local buffer overflow vulnerability in the Command Line input field that allows attackers to
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerabil
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts
Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the applica
10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that all
Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect
UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect a
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulner
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo
AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU regi
FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attac
ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode inte
In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username fie
Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute a
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject a
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v
DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar
In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du
In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confu
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the co
In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate file
In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path
In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalat
In multiple locations, there is a possible privilege escalation due to a confused deputy. This could lead to local esca
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This cou
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a log
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started