Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1142/1152
CVE-2026-34491

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls M

CVE-2026-9254

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, B

CVE-2026-39975

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly

CVE-2026-78541

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenti

CVE-2026-78551

RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to

CVE-2026-78553

RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil

CVE-2026-78555

RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug

CVE-2026-75542

Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositor

CVE-2026-75554

Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from

CVE-2026-77634

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their res

CVE-2026-77635

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas

CVE-2026-45404

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's

CVE-2026-77337

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio

CVE-2026-53532

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

0.0
CVE-2026-54920

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

CVE-2026-55371

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used

CVE-2026-16434

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH

CVE-2026-65633

Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as fu

CVE-2026-66882

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows

CVE-2026-17548

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who

CVE-2026-56092

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requ

CVE-2026-56093

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user

CVE-2026-56094

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the syste

CVE-2026-56095

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() functi

CVE-2026-56096

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syn

CVE-2026-77127

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to se

CVE-2026-77128

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user

CVE-2026-77129

The extension passes an editor-configurable email subject string directly into a Fluid template source without restricti

CVE-2026-77130

The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control

CVE-2026-77131

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encr

CVE-2026-77133

The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the prof

CVE-2026-77134

The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a re

CVE-2026-77135

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target

CVE-2026-77136

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly i

CVE-2026-77137

The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged b

CVE-2026-77138

The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserial

CVE-2026-77139

The extension fails to validate a client-supplied template element key before using it to build file paths for saving an

CVE-2026-77140

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in

CVE-2026-77141

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and

CVE-2026-77142

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for c

CVE-2026-77143

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modi

CVE-2026-77144

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the

CVE-2026-77145

The permission check for the frontend management update flow verified a different event than the one the request went on

CVE-2026-77146

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-exi

CVE-2026-12878

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin per

CVE-2026-12600

Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork develop

CVE-2026-57909

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to e

CVE-2026-57910

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen

CVE-2026-77996

Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping i

CVE-2026-77997

Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A miss

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started