Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 114/436
6.4
CVE-2026-18702

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost

6.4
CVE-2026-18708

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus

6.4
CVE-2026-18709

An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit

6.4
CVE-2026-64927

A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio

6.4
CVE-2026-19050

The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca

6.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated us

6.4
CVE-2026-72787

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft na

6.4
CVE-2026-3639

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `pp

6.4
CVE-2026-15948

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.4
CVE-2026-17090

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site

6.4
CVE-2026-11780

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.4
CVE-2026-15066

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in a

6.4
CVE-2026-15726

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in

6.4
CVE-2026-15604

The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin

6.4
CVE-2026-15790

The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,

6.4
CVE-2026-16758

The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all

6.4
CVE-2026-16775

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros

6.4
CVE-2026-18402

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v

6.4
CVE-2026-2357

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcod

6.4
CVE-2026-75010

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modobo

6.4
CVE-2026-12520

The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7

6.4
CVE-2026-70712

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

6.4
CVE-2026-71090

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.4
CVE-2026-71119

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.4
CVE-2026-47699

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From

6.4
CVE-2026-15421

The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site

6.4
CVE-2026-15446

The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load A

6.4
CVE-2026-50720

The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output

6.4
CVE-2026-76255

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power"

6.4
CVE-2026-76323

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

6.4
CVE-2026-76327

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

6.4
CVE-2026-76329

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who h

6.4
CVE-2026-76334

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

6.4
CVE-2026-76349

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated use

6.4
CVE-2026-72846

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/b

6.4
CVE-2026-4559

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dela

6.4
CVE-2026-4561

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form respon

6.4
CVE-2026-78269

Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.

6.4
CVE-2026-9728

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->si

6.4
CVE-2026-76837

Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/acco

6.4
CVE-2025-9878

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cr

6.4
CVE-2026-75019

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress

6.4
CVE-2026-19943

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.4
CVE-2026-76063

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi

6.4
CVE-2026-12561

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in a

6.4
CVE-2026-18100

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stor

6.4
CVE-2026-18512

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross

6.4
CVE-2026-76128

The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode At

6.4
CVE-2026-18547

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi

6.4
CVE-2026-79717

A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started