Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 104/129
9.3
CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

9.3
CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

9.3
CVE-2026-62835

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

9.3
CVE-2026-59527

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

9.3
CVE-2026-59533

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

9.3
CVE-2026-59538

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

9.3
CVE-2026-59549

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

9.3
CVE-2026-59550

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

9.3
CVE-2026-64740

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i

9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's s

9.3
CVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 th

9.3
CVE-2026-58155

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.

9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica

9.3
CVE-2026-47876

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with

9.3
CVE-2026-11707

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc

9.3
CVE-2026-66418

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack

9.3
CVE-2026-66421

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to

9.3
CVE-2026-15958

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its

9.3
CVE-2026-9273

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password r

9.3
CVE-2026-9195

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a

9.3
CVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

9.3
CVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

9.3
CVE-2026-65546

Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

9.3
CVE-2026-66447

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

9.3
CVE-2026-18367

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS

9.3
CVE-2026-59118

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

9.3
CVE-2026-47754

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19

9.3
CVE-2026-73080

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re

9.3
CVE-2026-70306

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

9.3
CVE-2026-73090

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi

9.3
CVE-2026-66659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome

9.3
CVE-2026-59506

: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (develop

9.3
CVE-2026-59507

: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control v

9.3
CVE-2026-28001

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

9.3
CVE-2026-28142

Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

9.3
CVE-2026-61966

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

9.3
CVE-2026-61969

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

9.3
CVE-2026-66436

Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.

9.3
CVE-2026-66446

Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

9.3
CVE-2026-66458

Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.

9.3
CVE-2026-66472

Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

9.3
CVE-2026-66478

Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

9.3
CVE-2026-17181

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path t

9.3
CVE-2026-72085

In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command inste

9.3
CVE-2026-72239

In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MS

9.3
CVE-2026-72277

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't norm

9.3
CVE-2026-72278

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting

9.3
CVE-2026-72288

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt aff

9.3
CVE-2026-72289

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours

9.3
CVE-2026-72291

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in try_get_locked_pte(

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started