Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1003/1152
4.3
CVE-2026-67616

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi

4.3
CVE-2026-18721

A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file

4.3
CVE-2026-12698

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei

4.3
CVE-2026-16035

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP

4.3
CVE-2026-16056

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler

4.3
CVE-2026-16295

The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p

4.3
CVE-2026-16546

The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA

4.3
CVE-2026-70484

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac

4.3
CVE-2026-70488

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync

4.3
CVE-2026-18819

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul

4.3
CVE-2026-18903

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so

4.3
CVE-2026-16613

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable

4.3
CVE-2026-17515

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio

4.3
CVE-2026-55996

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com

4.3
CVE-2026-7105

The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on

4.3
CVE-2026-71240

DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta

4.3
CVE-2026-71246

Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s

4.3
CVE-2026-71250

Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex

4.3
CVE-2026-15656

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook

4.3
CVE-2026-70596

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user

4.3
CVE-2026-20308

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta

4.3
CVE-2026-70427

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names du

4.3
CVE-2026-70428

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file pa

4.3
CVE-2026-70433

Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t

4.3
CVE-2026-70436

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p

4.3
CVE-2026-70438

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overal

4.3
CVE-2026-70442

Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credenti

4.3
CVE-2026-70443

Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials looku

4.3
CVE-2026-70444

A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overa

4.3
CVE-2026-70445

Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permissio

4.3
CVE-2026-70446

Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to

4.3
CVE-2026-70447

Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission

4.3
CVE-2026-70618

Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user

4.3
CVE-2026-18968

A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue

4.3
CVE-2026-18995

A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f

4.3
CVE-2025-11850

When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us

4.3
CVE-2025-13909

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT

4.3
CVE-2025-9266

The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check

4.3
CVE-2026-19037

A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_

4.3
CVE-2026-70556

Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h

4.3
CVE-2026-16316

OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame

4.3
CVE-2026-15246

The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no

4.3
CVE-2026-66678

Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.

4.3
CVE-2026-66681

Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.

4.3
CVE-2026-66692

Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10

4.3
CVE-2026-66696

Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.

4.3
CVE-2026-18276

Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated us

4.3
CVE-2025-6508

The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b

4.3
CVE-2026-14306

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co

4.3
CVE-2026-19064

A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started