Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1033/1152
3.5
CVE-2026-12130

A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of t

3.5
CVE-2026-9061

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o

3.5
CVE-2026-0129

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote informa

3.5
CVE-2026-0130

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to

3.5
CVE-2026-35068

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a

3.5
CVE-2026-12047

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi

3.5
CVE-2026-56330

Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept

3.5
CVE-2026-12812

A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of th

3.5
CVE-2025-15619

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin

3.5
CVE-2026-52796

Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic

3.5
CVE-2026-57522

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()

3.5
CVE-2026-3472

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image render

3.5
CVE-2026-13504

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code o

3.5
CVE-2026-13558

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown proces

3.5
CVE-2026-13570

A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f

3.5
CVE-2026-9836

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

3.5
CVE-2025-13475

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be

3.5
CVE-2026-14752

A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This a

3.5
CVE-2026-14791

A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of

3.5
CVE-2026-8801

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer:

3.5
CVE-2025-12506

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and

3.5
CVE-2026-59213

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all

3.5
CVE-2026-15311

A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma

3.5
CVE-2026-59791

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

3.5
CVE-2026-61492

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

3.5
CVE-2026-15493

A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. Thi

3.5
CVE-2026-15505

A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra

3.5
CVE-2026-15678

A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of t

3.5
CVE-2026-47086

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe

3.5
CVE-2026-47087

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A

3.5
CVE-2024-32389

Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack

3.5
CVE-2026-16073

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S

3.5
CVE-2026-54244

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp

3.5
CVE-2026-16155

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

3.5
CVE-2026-16156

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par

3.5
CVE-2026-16202

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i

3.5
CVE-2026-16203

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

3.5
CVE-2026-47000

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security F

3.5
CVE-2026-64800

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

3.5
CVE-2026-56537

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar

3.5
CVE-2026-56538

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi

3.5
CVE-2026-48051

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy

3.5
CVE-2026-14819

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin

3.5
CVE-2026-17902

Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to le

3.5
CVE-2026-13393

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item

3.5
CVE-2026-10827

The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi

3.5
CVE-2026-16068

The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does

3.5
CVE-2025-15677

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin

3.5
CVE-2026-19209

A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file

3.5
CVE-2026-19230

A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started