Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 10/42
3.7
CVE-2026-19906

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the

3.7
CVE-2026-19965

A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordRe

3.7
CVE-2026-74887

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op

3.7
CVE-2026-75773

A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the f

3.7
CVE-2026-75774

A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the

3.7
CVE-2026-60589

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

3.7
CVE-2026-60853

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

3.7
CVE-2026-62533

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

3.7
CVE-2026-70682

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

3.7
CVE-2026-70785

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

3.7
CVE-2026-70848

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

3.7
CVE-2026-71080

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

3.7
CVE-2026-73923

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

3.7
CVE-2026-16888

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a pat

3.7
CVE-2026-73542

Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an at

3.7
CVE-2026-49996

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se

3.7
CVE-2026-77151

A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of t

3.7
CVE-2026-77640

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncat

3.7
CVE-2026-49245

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on bro

3.7
CVE-2026-18356

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist ca

3.7
CVE-2026-78049

A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVar

3.7
CVE-2026-19565

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock

3.7
CVE-2026-72701

Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string compar

3.7
CVE-2026-21758

HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive inf

3.7
CVE-2026-78886

A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/s

3.7
CVE-2026-78887

A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th

3.7
CVE-2026-80199

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers t

3.7
CVE-2026-19220

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network be

3.7
CVE-2026-47843

In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrect

3.7
CVE-2025-62341

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo

3.7
CVE-2026-81723

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that

3.7
CVE-2026-81725

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac

3.7
CVE-2026-54713

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() gener

3.7
CVE-2026-59277

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an

3.7
CVE-2026-81836

A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file sr

3.7
CVE-2026-40203

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes

3.7
CVE-2026-13735

Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_da

3.7
CVE-2026-77063

multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter

3.7
CVE-2026-55785

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptograph

3.7
CVE-2026-82562

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value un

3.7
CVE-2026-82555

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAu

3.6
CVE-2026-2345

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.add

3.6
CVE-2026-0995

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to

3.6
CVE-2026-31863

Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca

3.6
CVE-2026-24509

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A l

3.6
CVE-2026-32722

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process

3.6
CVE-2026-32018

OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegis

3.6
CVE-2026-35386

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r

3.6
CVE-2026-35362

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) s

3.6
CVE-2026-41962

Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulne

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started