Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1011/1152
4.3
CVE-2026-55227

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s

4.3
CVE-2026-62249

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.3
CVE-2026-47850

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP

4.3
CVE-2026-16568

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

4.3
CVE-2026-16569

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

4.3
CVE-2026-78138

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sal

4.3
CVE-2026-78139

The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one

4.3
CVE-2026-5218

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Techno

4.3
CVE-2026-59280

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a control

4.3
CVE-2026-80209

The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes

4.3
CVE-2026-59319

RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w

4.3
CVE-2026-79995

The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email c

4.3
CVE-2026-9491

A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote au

4.3
CVE-2026-33263

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused b

4.3
CVE-2026-33607

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of

4.3
CVE-2026-40013

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an

4.3
CVE-2026-40015

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands

4.3
CVE-2026-42008

Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentica

4.3
CVE-2026-42392

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to b

4.3
CVE-2026-42395

A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process

4.3
CVE-2026-82111

A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of

4.3
CVE-2026-82257

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi

4.3
CVE-2026-81284

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

4.3
CVE-2026-81299

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

4.3
CVE-2026-81761

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

4.3
CVE-2026-55064

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin

4.3
CVE-2026-55547

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from

4.3
CVE-2026-55566

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext

4.3
CVE-2026-55834

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0,

4.3
CVE-2026-66798

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

4.3
CVE-2026-18545

IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat

4.3
CVE-2026-55696

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se

4.3
CVE-2026-80311

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th

4.3
CVE-2026-81346

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX

4.3
CVE-2026-82633

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API

4.3
CVE-2026-82544

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th

4.3
CVE-2026-82658

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authent

4.3
CVE-2026-82552

A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown

4.3
CVE-2026-82554

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_c

4.3
CVE-2026-82587

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_m

4.3
CVE-2026-82588

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/na

4.3
CVE-2026-82589

A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_

4.3
CVE-2026-82590

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of t

4.3
CVE-2026-82601

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a mani

4.3
CVE-2026-82604

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language M

4.2
CVE-2025-68492

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln

4.2
CVE-2025-43904

In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user

4.2
CVE-2026-21922

Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th

4.2
CVE-2026-21979

Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th

4.2
CVE-2026-23955

EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started