Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1133/1152
CVE-2026-40144

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Window

CVE-2026-64865

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-

CVE-2026-64866

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 un

CVE-2026-40145

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility a

CVE-2026-61666

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a

CVE-2026-68518

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/ac

CVE-2026-54284

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion

CVE-2026-59894

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape ex

CVE-2026-68519

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions

CVE-2026-71491

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py

CVE-2026-74253

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 -

CVE-2026-74254

Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vuln

CVE-2026-12553

HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read fro

CVE-2026-17639

Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an

CVE-2026-52886

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute

CVE-2026-71553

ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id acce

CVE-2026-71858

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortc

CVE-2026-35219

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps

CVE-2026-47683

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js

CVE-2026-75529

Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download

CVE-2026-75531

Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted

CVE-2026-11817

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments a

CVE-2026-43971

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via une

CVE-2026-18929

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The

CVE-2026-75838

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hoo

CVE-2026-18751

External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App:

CVE-2026-1199

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly co

CVE-2026-23922

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a mali

CVE-2026-23929

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter proces

CVE-2026-23930

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically cra

CVE-2026-23931

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values

CVE-2026-23933

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed

CVE-2026-23934

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically craft

CVE-2026-23935

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript

CVE-2026-23937

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential

CVE-2026-23938

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/sc

CVE-2026-45532

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnera

CVE-2026-59781

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether th

CVE-2026-17084

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoi

CVE-2026-68939

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read ac

CVE-2026-71539

n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation

CVE-2026-75872

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers

CVE-2026-15806

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HT

CVE-2026-62357

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INIT

CVE-2026-63328

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct pat

CVE-2026-71574

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

CVE-2026-72532

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - A

CVE-2026-73073

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim co

CVE-2026-73337

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks

CVE-2026-73371

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started