Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1008/1152
4.3
CVE-2026-76380

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run

4.3
CVE-2026-76381

In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permissio

4.3
CVE-2026-76382

In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76383

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with perm

4.3
CVE-2026-76384

In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission

4.3
CVE-2026-76385

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76386

In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could ex

4.3
CVE-2026-76398

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the

4.3
CVE-2026-76405

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S

4.3
CVE-2026-14953

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges

4.3
CVE-2026-73196

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize

4.3
CVE-2026-63015

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template inf

4.3
CVE-2026-53584

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

4.3
CVE-2026-61663

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

4.3
CVE-2026-64777

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of wha

4.3
CVE-2026-62945

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-contr

4.3
CVE-2026-20679

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta

4.3
CVE-2026-77391

A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This a

4.3
CVE-2026-65645

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP metho

4.3
CVE-2026-61422

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. Whe

4.3
CVE-2026-65613

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while lis

4.3
CVE-2026-62313

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte

4.3
CVE-2026-33047

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass

4.3
CVE-2026-53487

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove

4.3
CVE-2026-53541

OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in

4.3
CVE-2026-76057

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

4.3
CVE-2026-76074

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

4.3
CVE-2026-4245

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0

4.3
CVE-2026-4244

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

4.3
CVE-2026-5093

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da

4.3
CVE-2026-78054

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function

4.3
CVE-2026-78055

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vul

4.3
CVE-2026-78059

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of

4.3
CVE-2026-78060

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of t

4.3
CVE-2026-14853

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a

4.3
CVE-2026-77116

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-

4.3
CVE-2026-78145

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/u

4.3
CVE-2026-78186

A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the

4.3
CVE-2026-78280

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

4.3
CVE-2026-21759

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  A

4.3
CVE-2026-78250

A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component

4.3
CVE-2026-78417

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a

4.3
CVE-2026-77923

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in

4.3
CVE-2026-55468

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o

4.3
CVE-2026-10630

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress

4.3
CVE-2026-19801

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera

4.3
CVE-2026-75930

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve

4.3
CVE-2026-78466

The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and

4.3
CVE-2026-78467

The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a

4.3
CVE-2026-75908

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started