2026
57,566 vulnerabilities published in 2026
Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privileg
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur
FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-
An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain l
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved thr
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori
Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Ove
Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and a
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al
Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically presen
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when i
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4,
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorr
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorr
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Inco
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorr
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e
A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even afte
Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting
A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/co
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller c
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-p
A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath
Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API e
The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started