Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1007/1152
4.3
CVE-2026-75090

A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_ggu

4.3
CVE-2026-75093

A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_al

4.3
CVE-2026-75151

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vu

4.3
CVE-2026-74903

SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which

4.3
CVE-2026-75832

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a

4.3
CVE-2026-75835

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuth

4.3
CVE-2026-75839

ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerabil

4.3
CVE-2026-75841

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticat

4.3
CVE-2026-74971

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Fi

4.3
CVE-2026-74972

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ES

4.3
CVE-2026-66634

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

4.3
CVE-2026-70657

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined

4.3
CVE-2026-74003

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

4.3
CVE-2026-74006

Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

4.3
CVE-2026-45121

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistentl

4.3
CVE-2026-45122

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissio

4.3
CVE-2026-45123

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6

4.3
CVE-2026-45124

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consis

4.3
CVE-2026-47245

MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate

4.3
CVE-2026-63640

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the ca

4.3
CVE-2026-71322

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership che

4.3
CVE-2026-76032

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/

4.3
CVE-2026-70683

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

4.3
CVE-2026-71124

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Suppo

4.3
CVE-2026-76041

Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web or

4.3
CVE-2026-62289

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containin

4.3
CVE-2026-62377

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by h

4.3
CVE-2025-11729

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc

4.3
CVE-2026-14196

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allow

4.3
CVE-2026-16979

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on tw

4.3
CVE-2026-19416

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified

4.3
CVE-2026-76166

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multica

4.3
CVE-2026-76209

phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing atta

4.3
CVE-2026-76211

phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elas

4.3
CVE-2026-40509

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter

4.3
CVE-2026-76614

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel PO

4.3
CVE-2026-55703

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id}

4.3
CVE-2026-16849

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an impro

4.3
CVE-2026-16886

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o

4.3
CVE-2026-54492

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view

4.3
CVE-2026-76576

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDownload/resourceDownloa

4.3
CVE-2026-76256

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

4.3
CVE-2026-76309

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "ad

4.3
CVE-2026-76360

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to

4.3
CVE-2026-76370

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational

4.3
CVE-2026-76374

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76376

In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76377

In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run action

4.3
CVE-2026-76378

In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permissi

4.3
CVE-2026-76379

In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions c

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started