Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1114/1152
CVE-2026-54202

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct

CVE-2026-54203

Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti

CVE-2026-54204

Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t

CVE-2026-54205

Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”

CVE-2026-54206

Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh

CVE-2026-54207

Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi

CVE-2026-54208

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated

CVE-2026-54209

Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t

CVE-2026-54210

Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable

CVE-2026-54211

Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o

CVE-2026-54212

Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow

CVE-2026-54213

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down whe

CVE-2026-54214

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par

CVE-2026-54215

Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta

CVE-2026-54216

Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By

CVE-2026-54217

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send

CVE-2026-54218

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally

CVE-2026-48094

The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse

CVE-2026-66494

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut

CVE-2026-15570

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245

CVE-2026-66914

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated

CVE-2026-62992

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio

CVE-2026-62996

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From

CVE-2026-66059

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose

CVE-2026-14644

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with

CVE-2026-17593

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi

CVE-2026-17594

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th

CVE-2026-17595

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select

CVE-2026-17596

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre

CVE-2026-17597

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f

CVE-2026-17598

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when

CVE-2026-17599

Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th

CVE-2026-17600

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio

CVE-2026-17601

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their

CVE-2026-17603

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data

CVE-2026-67585

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent

CVE-2026-64638

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici

CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo

CVE-2026-66000

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation

CVE-2026-69127

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl

CVE-2026-71847

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume

CVE-2026-71852

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and larg

CVE-2026-47659

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47660

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47661

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-48007

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to

CVE-2026-71870

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti

CVE-2026-46358

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi

CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47663

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started