Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1145/1152
CVE-2020-15876

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

CVE-2020-15878

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

CVE-2026-35445

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d

CVE-2023-42179

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, pass

CVE-2025-29419

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

CVE-2026-76784

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communicatio

CVE-2026-19485

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versi

CVE-2025-70293

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b

CVE-2025-70340

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms

CVE-2026-26445

stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP co

CVE-2026-54245

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional a

CVE-2026-66003

Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access

CVE-2026-68000

The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directl

CVE-2026-75327

In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arb

CVE-2026-75334

The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql para

CVE-2026-15973

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries admin

CVE-2026-52103

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before

CVE-2026-52473

An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concaten

CVE-2026-75363

An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /c

CVE-2026-75364

Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/web

CVE-2026-75411

JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy

CVE-2026-75413

DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize th

CVE-2026-75414

In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which l

CVE-2026-75415

AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid f

CVE-2026-79921

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client

CVE-2026-16809

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation wor

CVE-2026-55182

LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable

CVE-2026-58070

A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user

CVE-2026-63360

LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the

CVE-2026-64632

A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.

CVE-2026-65641

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

CVE-2026-65642

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticate

CVE-2026-65646

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files

CVE-2026-65647

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as r

CVE-2026-65930

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacemen

CVE-2026-77298

SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an exter

CVE-2026-65956

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API

CVE-2026-69129

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not

CVE-2026-80183

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-sc

CVE-2026-19398

“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a

CVE-2026-16895

A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service i

CVE-2026-77034

Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager

CVE-2026-77035

Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Eve

CVE-2026-77989

Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - bui

CVE-2026-77990

Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.

CVE-2026-77991

Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The admin

CVE-2026-74848

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An att

CVE-2026-75020

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A

CVE-2026-81659

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF e

CVE-2026-81662

Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. Whil

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started