Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1109/1152
CVE-2026-48058

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern

CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a

CVE-2026-54659

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18

CVE-2026-12895

SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries

CVE-2026-50642

diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application

CVE-2026-0667

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d

CVE-2026-12927

CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut

CVE-2026-14354

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize

CVE-2026-33385

A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig

CVE-2026-44943

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem

CVE-2026-44944

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc

CVE-2026-50641

Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in

CVE-2026-55995

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects

CVE-2026-9177

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se

CVE-2026-59247

Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo

CVE-2026-66723

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API.

CVE-2026-66724

MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u

CVE-2026-15228

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust

CVE-2026-16543

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr

CVE-2026-54078

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve

CVE-2026-54079

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30

CVE-2026-54080

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service

CVE-2026-54081

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service

CVE-2026-52791

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc

CVE-2026-54693

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4

CVE-2026-8338

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.

CVE-2026-8339

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus

CVE-2026-18236

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh

CVE-2026-12935

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based b

CVE-2026-62995

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar

CVE-2026-63118

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran

CVE-2026-67431

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran

CVE-2026-67433

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In

CVE-2026-67435

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve

CVE-2026-67436

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In

CVE-2026-59952

Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper wh

CVE-2026-15929

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma

CVE-2026-16727

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows

CVE-2026-13584

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Ele

CVE-2026-18353

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer a

CVE-2022-4994

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __

CVE-2026-18363

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.

CVE-2026-53431

Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previous

CVE-2026-54885

Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAu

CVE-2026-65635

Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attack

CVE-2026-54722

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_

CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code

CVE-2026-59881

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client ac

CVE-2026-64870

MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool p

CVE-2026-66066

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started