Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 112/436
6.4
CVE-2026-36214

osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable

6.4
CVE-2026-55000

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

6.4
CVE-2026-57097

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical atta

6.4
CVE-2026-4018

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local acce

6.4
CVE-2026-24220

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an uns

6.4
CVE-2026-24259

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critic

6.4
CVE-2026-56352

n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option,

6.4
CVE-2026-60062

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files ou

6.4
CVE-2026-56678

9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key

6.4
CVE-2026-14987

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting

6.4
CVE-2026-15652

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S

6.4
CVE-2026-13755

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_

6.4
CVE-2026-15021

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v

6.4
CVE-2026-15099

The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute

6.4
CVE-2026-63397

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t

6.4
CVE-2026-2594

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi

6.4
CVE-2026-15161

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and

6.4
CVE-2026-15759

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t

6.4
CVE-2026-12705

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue a

6.4
CVE-2026-45703

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport expor

6.4
CVE-2026-63743

SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us

6.4
CVE-2026-12900

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S

6.4
CVE-2026-64626

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en

6.4
CVE-2026-15156

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored

6.4
CVE-2026-15145

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored

6.4
CVE-2026-60158

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

6.4
CVE-2026-60183

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported v

6.4
CVE-2026-60331

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

6.4
CVE-2026-60332

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Su

6.4
CVE-2026-60620

Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Manage

6.4
CVE-2026-60864

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

6.4
CVE-2026-61023

Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S

6.4
CVE-2026-61143

Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: P

6.4
CVE-2026-61190

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

6.4
CVE-2026-61217

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supp

6.4
CVE-2026-15787

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu

6.4
CVE-2026-9635

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame

6.4
CVE-2026-9729

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti

6.4
CVE-2026-14481

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl

6.4
CVE-2026-15394

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross

6.4
CVE-2026-15404

The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc

6.4
CVE-2026-15646

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri

6.4
CVE-2026-15794

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shor

6.4
CVE-2025-9205

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.

6.4
CVE-2026-15100

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore

6.4
CVE-2026-6454

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu

6.4
CVE-2026-15333

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress

6.4
CVE-2026-15334

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress

6.4
CVE-2026-15464

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att

6.4
CVE-2026-15648

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started