Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1054/1152
2.7
CVE-2026-48074

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

2.7
CVE-2026-16957

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed

2.7
CVE-2026-48412

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att

2.7
CVE-2026-55984

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

2.7
CVE-2026-58445

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

2.7
CVE-2026-58511

Webhook Authorization Header Returned in Plaintext via API

2.7
CVE-2026-17071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traver

2.7
CVE-2026-19837

A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/

2.7
CVE-2026-62684

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

2.7
CVE-2026-13173

The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before ass

2.7
CVE-2026-14825

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa

2.7
CVE-2026-14826

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE

2.7
CVE-2026-19406

The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t

2.7
CVE-2026-76361

In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c

2.7
CVE-2026-76368

In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta

2.7
CVE-2026-76369

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto

2.7
CVE-2026-76371

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r

2.7
CVE-2026-19699

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint

2.7
CVE-2026-16577

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c

2.7
CVE-2026-19085

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic

2.7
CVE-2026-19435

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo

2.7
CVE-2026-66721

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def

2.7
CVE-2026-13176

The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify eve

2.7
CVE-2026-14187

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al

2.7
CVE-2026-77003

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c

2.7
CVE-2026-79777

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p

2.7
CVE-2026-9805

SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size

2.7
CVE-2026-79615

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba

2.7
CVE-2026-77704

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req

2.7
CVE-2026-81200

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa

2.6
CVE-2025-61873

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor

2.6
CVE-2026-27632

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar a

2.6
CVE-2026-21725

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w

2.6
CVE-2025-27769

A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC

2.6
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue

2.6
CVE-2026-32058

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos

2.6
CVE-2025-55274

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo

2.6
CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us

2.6
CVE-2026-7845

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.toby

2.6
CVE-2026-7846

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the

2.6
CVE-2026-7847

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_

2.6
CVE-2025-31957

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t

2.6
CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose

2.6
CVE-2026-6883

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18

2.6
CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may

2.6
CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive

2.6
CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce

2.6
CVE-2026-45154

Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous

2.6
CVE-2026-45155

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 an

2.6
CVE-2026-9694

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started