Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 105/129
9.3
CVE-2026-72329

In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR

9.3
CVE-2026-72412

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_UNUSED pte bit The

9.3
CVE-2026-72495

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to allocate W

9.3
CVE-2026-74310

In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubufs only once vhost

9.3
CVE-2026-74439

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down s

9.3
CVE-2026-74517

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling befo

9.3
CVE-2026-74568

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and

9.3
CVE-2026-74573

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stre

9.3
CVE-2026-74799

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authenticatio

9.3
CVE-2026-71566

FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end

9.3
CVE-2026-55674

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated

9.3
CVE-2026-64849 KEV

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior t

9.3
CVE-2026-75626

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and me

9.3
CVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

9.3
CVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

9.3
CVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

9.3
CVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

9.3
CVE-2026-73392

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

9.3
CVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

9.3
CVE-2026-45118

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or pro

9.3
CVE-2026-75913

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the

9.3
CVE-2026-67921

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and

9.3
CVE-2026-62613

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

9.3
CVE-2026-62618

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

9.3
CVE-2026-62637

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

9.3
CVE-2026-70673

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

9.3
CVE-2026-70855

Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported

9.3
CVE-2026-70998

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

9.3
CVE-2026-71037

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

9.3
CVE-2026-71065

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

9.3
CVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

9.3
CVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

9.3
CVE-2026-73388

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

9.3
CVE-2026-73391

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

9.3
CVE-2026-47187

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can retu

9.3
CVE-2026-66794

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows

9.3
CVE-2026-16822

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and mod

9.3
CVE-2025-15688

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

9.3
CVE-2026-66592

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

9.3
CVE-2026-66593

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

9.3
CVE-2026-66609

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

9.3
CVE-2026-66649

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

9.3
CVE-2026-66680

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

9.3
CVE-2026-68566

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

9.3
CVE-2026-71428

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc

9.3
CVE-2026-17422

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer ove

9.3
CVE-2026-62834

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil

9.3
CVE-2026-74712

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys(

9.3
CVE-2026-32551

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

9.3
CVE-2026-32554

Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started