Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 101/129
9.3
CVE-2026-44225

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.

9.3
CVE-2025-27851

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac

9.3
CVE-2026-44212

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scriptin

9.3
CVE-2026-8950

Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14

9.3
CVE-2026-39531

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W

9.3
CVE-2026-9264

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution an

9.3
CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut

9.3
CVE-2026-42773

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOn

9.3
CVE-2026-42774

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngi

9.3
CVE-2026-44451

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied

9.3
CVE-2026-42727

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active

9.3
CVE-2026-42740

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan

9.3
CVE-2026-42747

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas

9.3
CVE-2026-42755

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn

9.3
CVE-2026-42761

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active

9.3
CVE-2026-44590

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workfl

9.3
CVE-2026-42672

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W

9.3
CVE-2026-42684

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta

9.3
CVE-2026-42849

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st

9.3
CVE-2026-50751 KEV

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows

9.3
CVE-2026-46316

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re

9.3
CVE-2026-34691

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting

9.3
CVE-2026-45328

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen

9.3
CVE-2026-53475

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connecti

9.3
CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc

9.3
CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport

9.3
CVE-2026-50090

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due

9.3
CVE-2026-44990

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer wi

9.3
CVE-2026-39441

Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.

9.3
CVE-2026-39492

Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

9.3
CVE-2026-39493

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

9.3
CVE-2026-39502

Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

9.3
CVE-2026-39511

Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

9.3
CVE-2026-39512

Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

9.3
CVE-2026-39519

Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.

9.3
CVE-2026-39530

Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.

9.3
CVE-2026-40771

Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.

9.3
CVE-2026-40798

Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.

9.3
CVE-2026-42381

Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

9.3
CVE-2026-42386

Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.

9.3
CVE-2026-42639

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

9.3
CVE-2026-42665

Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

9.3
CVE-2026-45439

Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

9.3
CVE-2026-48886

Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

9.3
CVE-2026-49067

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

9.3
CVE-2026-49776

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websit

9.3
CVE-2026-52693

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

9.3
CVE-2026-39574

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

9.3
CVE-2026-49772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell

9.3
CVE-2026-52715

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started