Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Trending Vulnerabilities

The most severe recently published CVEs — CVSS 7.0 and above, ranked by score and recency.

100
Critical
0
High
2
Known Exploited
100 results · Page 2/2
51 10.0
CVE-2026-72851

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXE

52 10.0
CVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

53 10.0
CVE-2026-27544

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

54 10.0
CVE-2026-59500

: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)

55 10.0
CVE-2026-15413

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-

56 10.0
CVE-2024-27253

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform

57 10.0
CVE-2026-73299

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks r

58 10.0
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit

59 10.0
CVE-2026-71398

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

60 10.0
CVE-2026-27302

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

61 10.0
CVE-2026-48362

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

62 10.0
CVE-2026-17061

A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2

63 10.0
CVE-2026-48056

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro

64 10.0
CVE-2026-58115

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In

65 10.0
CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf

66 10.0
CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes

67 10.0
CVE-2026-72898 KEV

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a

68 10.0
CVE-2026-65667

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

69 10.0
CVE-2026-63508

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev

70 10.0
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

71 10.0
CVE-2026-14812

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator

72 10.0
CVE-2026-11976

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both

73 10.0
CVE-2026-66665

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

74 10.0
CVE-2026-65553

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

75 10.0
CVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support

76 10.0
CVE-2026-48168

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln

77 10.0
CVE-2026-16940

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un

78 10.0
CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv

79 10.0
CVE-2026-48330

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL

80 10.0
CVE-2026-48323

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul

81 10.0
CVE-2026-69085

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s

82 10.0
CVE-2026-69084

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement

83 10.0
CVE-2026-69083

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable

84 10.0
CVE-2026-18452

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att

85 10.0
CVE-2026-66803

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

86 10.0
CVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

87 10.0
CVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi

88 10.0
CVE-2026-16326

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may all

89 10.0
CVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0

90 10.0
CVE-2026-58162

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue a

91 10.0
CVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This

92 10.0
CVE-2026-57834

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser

93 10.0
CVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0

94 10.0
CVE-2026-16498

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H

95 10.0
CVE-2026-11756

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3

96 10.0
CVE-2026-16812 KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile

97 10.0
CVE-2026-66012

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated onl

98 10.0
CVE-2026-58630

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

99 10.0
CVE-2026-57106

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

100 10.0
CVE-2026-56163

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el

Stay Ahead of Threats

CyberStrike continuously monitors for trending vulnerabilities and scans your infrastructure automatically.

Get Started