Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1136/1152
CVE-2026-55191

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX

CVE-2026-55192

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can ret

CVE-2026-55193

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accep

CVE-2026-55194

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp

CVE-2026-55648

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in l

CVE-2026-62681

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-62682

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-63633

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/

CVE-2026-63652

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels

CVE-2026-67581

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources

CVE-2026-71864

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-71865

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-71866

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8

CVE-2026-71867

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-71868

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-71869

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-71871

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-72716

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-72717

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.

CVE-2026-73136

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by

CVE-2026-73541

Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the

CVE-2026-73829

Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one c

CVE-2026-19198

Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.Thi

CVE-2026-55483

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission ca

CVE-2026-55643

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access

CVE-2026-55694

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_i

CVE-2026-61807

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the

CVE-2026-75618

Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local networ

CVE-2026-75619

Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on

CVE-2026-54742

Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moder

CVE-2026-55090

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpola

CVE-2026-61711

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P

CVE-2026-61712

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P

CVE-2026-63188

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package

CVE-2026-68560

Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj

CVE-2026-75112

A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor

CVE-2026-75593

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P

CVE-2026-54494

Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_va

CVE-2026-54739

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in cra

CVE-2026-54741

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy blocks new private me

CVE-2026-54743

Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Mark

CVE-2026-61556

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the stri

CVE-2026-68554

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append att

CVE-2026-75595

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.h

CVE-2026-75596

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the defau

CVE-2026-75616

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing c

CVE-2026-76878

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is se

CVE-2026-8619

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.

0.0
CVE-2026-19582

In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code

CVE-2025-14602

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started