Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1004/1152
4.3
CVE-2026-19066

A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk

4.3
CVE-2026-64664

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont

4.3
CVE-2026-17264

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of

4.3
CVE-2026-15214

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription

4.3
CVE-2026-19212

A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WT

4.3
CVE-2026-19213

A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo

4.3
CVE-2026-19014

Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti

4.3
CVE-2026-59717

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr

4.3
CVE-2026-16965

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a

4.3
CVE-2026-19378

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the

4.3
CVE-2026-17020

The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle

4.3
CVE-2026-18200

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user

4.3
CVE-2026-18666

The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor

4.3
CVE-2026-56620

HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor

4.3
CVE-2026-72722

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_

4.3
CVE-2026-72724

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c

4.3
CVE-2026-12624

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra

4.3
CVE-2026-72732

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp

4.3
CVE-2026-72906

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email

4.3
CVE-2026-72912

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec

4.3
CVE-2026-73035

npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t

4.3
CVE-2026-72919

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

4.3
CVE-2026-58244

SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati

4.3
CVE-2026-66761

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s

4.3
CVE-2026-66764

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user

4.3
CVE-2026-66772

SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer

4.3
CVE-2026-66775

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent

4.3
CVE-2026-14549

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

4.3
CVE-2026-19519

A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked

4.3
CVE-2026-72610

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

4.3
CVE-2026-59693

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.

4.3
CVE-2026-72785

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only

4.3
CVE-2026-19078

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the

4.3
CVE-2026-56720

CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that

4.3
CVE-2026-62882

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove

4.3
CVE-2026-18707

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se

4.3
CVE-2026-73229

Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's

4.3
CVE-2026-64934

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho

4.3
CVE-2025-15686

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com

4.3
CVE-2025-15687

A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF

4.3
CVE-2026-13177

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user

4.3
CVE-2026-13612

The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al

4.3
CVE-2026-14857

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his

4.3
CVE-2026-14858

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi

4.3
CVE-2026-14859

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a

4.3
CVE-2026-15388

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

4.3
CVE-2026-18046

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

4.3
CVE-2026-18962

The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int

4.3
CVE-2026-19052

The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac

4.3
CVE-2025-41771

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started