Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 102/129
9.3
CVE-2026-35305

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). T

9.3
CVE-2026-35306

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). T

9.3
CVE-2026-46785

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

9.3
CVE-2026-46795

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

9.3
CVE-2026-46805

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

9.3
CVE-2026-46912

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Sup

9.3
CVE-2026-46913

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Su

9.3
CVE-2026-22332

Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

9.3
CVE-2026-22340

Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

9.3
CVE-2026-39438

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

9.3
CVE-2026-39596

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

9.3
CVE-2026-48616

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L

9.3
CVE-2026-48745

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca

9.3
CVE-2026-48875

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

9.3
CVE-2026-49076

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

9.3
CVE-2026-49079

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

9.3
CVE-2026-49080

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

9.3
CVE-2026-49084

Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

9.3
CVE-2026-54186

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

9.3
CVE-2026-54187

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

9.3
CVE-2026-54811

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

9.3
CVE-2025-59554

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

9.3
CVE-2026-54808

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave

9.3
CVE-2026-54809

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U

9.3
CVE-2026-54815

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi

9.3
CVE-2026-54819

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd

9.3
CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot

9.3
CVE-2026-48768

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is

9.3
CVE-2026-12048

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL

9.3
CVE-2026-49871

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows

9.3
CVE-2026-55450

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can

9.3
CVE-2026-54836

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows

9.3
CVE-2026-54843

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

9.3
CVE-2026-54849

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

9.3
CVE-2026-54820

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

9.3
CVE-2026-54825

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

9.3
CVE-2026-54827

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

9.3
CVE-2026-54831

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

9.3
CVE-2026-56034

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

9.3
CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

9.3
CVE-2026-56062

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

9.3
CVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

9.3
CVE-2026-56068

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

9.3
CVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

9.3
CVE-2026-48313

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir

9.3
CVE-2026-48315

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re

9.3
CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative

9.3
CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative

9.3
CVE-2026-14038

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote atta

9.3
CVE-2026-55721

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started