Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1124/1152
CVE-2026-73500

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,

CVE-2026-15141

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests con

CVE-2026-47718

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` s

CVE-2026-46382

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a

CVE-2026-46688

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an

CVE-2026-0289

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user

CVE-2026-0290

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables

CVE-2026-0291

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Li

CVE-2026-0292

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enabl

CVE-2026-0293

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privil

CVE-2026-0294

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS device

CVE-2026-0295

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged

CVE-2026-0296

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attac

CVE-2026-0297

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (Mi

CVE-2026-0298

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo

CVE-2026-0299

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate

CVE-2026-16458

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to

CVE-2026-16459

Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and

CVE-2026-11970

This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DL

CVE-2026-16455

In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 throu

CVE-2026-18368

In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request

CVE-2026-45819

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input para

CVE-2026-73483

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/no

CVE-2026-73484

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas

CVE-2026-73485

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta

CVE-2026-73486

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows

CVE-2026-73487

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows una

CVE-2026-73488

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/

CVE-2026-73601

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTO

CVE-2026-73602

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated use

CVE-2026-73603

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing atta

CVE-2026-73627

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule en

CVE-2026-19716

Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authe

CVE-2026-19734

Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus

CVE-2026-65932

The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denia

CVE-2026-65933

A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vuln

CVE-2026-65934

An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E

CVE-2026-65935

Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key v

CVE-2026-65936

A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information

CVE-2026-73557

vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds

CVE-2026-19744

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute a

CVE-2026-55400

CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated

CVE-2026-55401

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 1

CVE-2026-55402

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with a

CVE-2026-73564

frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an

CVE-2026-73569

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until

CVE-2026-73645

OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0

CVE-2026-73648

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::

CVE-2026-73652

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-s

CVE-2026-45725

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compl

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started