Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Trending Vulnerabilities

The most severe recently published CVEs — CVSS 7.0 and above, ranked by score and recency.

100
Critical
0
High
2
Known Exploited
100 results · Page 1/2
1 10.0
CVE-2026-82542

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the fi

2 10.0
CVE-2026-82456

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c

3 10.0
CVE-2026-54745

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the

4 10.0
CVE-2026-82222

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af

5 10.0
CVE-2026-81735

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g

6 10.0
CVE-2026-81096

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat

7 10.0
CVE-2026-77554

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal

8 10.0
CVE-2026-77550

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo

9 10.0
CVE-2026-77537

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro

10 10.0
CVE-2026-79911

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the functio

11 10.0
CVE-2026-76197

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co

12 10.0
CVE-2026-76195

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co

13 10.0
CVE-2026-76193

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbi

14 10.0
CVE-2026-78167

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session

15 10.0
CVE-2026-74705

In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segment

16 10.0
CVE-2026-74612

In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adju

17 10.0
CVE-2026-77946

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe

18 10.0
CVE-2026-61539

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference

19 10.0
CVE-2026-69502

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a ne

20 10.0
CVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

21 10.0
CVE-2026-69555

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

22 10.0
CVE-2026-65816

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a

23 10.0
CVE-2026-65801

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov

24 10.0
CVE-2026-65770

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache

25 10.0
CVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans

26 10.0
CVE-2026-20358

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

27 10.0
CVE-2026-20357

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

28 10.0
CVE-2026-20317

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

29 10.0
CVE-2026-20315

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

30 10.0
CVE-2026-20030

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

31 10.0
CVE-2026-18051

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil

32 10.0
CVE-2026-76008

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-

33 10.0
CVE-2026-70921

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

34 10.0
CVE-2026-70880

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu

35 10.0
CVE-2026-61241

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor

36 10.0
CVE-2026-75784

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of th

37 10.0
CVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

38 10.0
CVE-2026-75874

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

39 10.0
CVE-2026-74843

A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function st

40 10.0
CVE-2026-19977

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_ur

41 10.0
CVE-2026-74475

In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircui

42 10.0
CVE-2026-74309

In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrup

43 10.0
CVE-2026-74280

In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wr

44 10.0
CVE-2026-74279

In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong lo

45 10.0
CVE-2026-72421

In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main t

46 10.0
CVE-2026-72408

In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on g

47 10.0
CVE-2026-72407

In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro

48 10.0
CVE-2026-73678

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that a

49 10.0
CVE-2026-19188

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vul

50 10.0
CVE-2026-72811

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backl

Stay Ahead of Threats

CyberStrike continuously monitors for trending vulnerabilities and scans your infrastructure automatically.

Get Started