Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1146/1152
CVE-2026-81672

SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video pa

CVE-2026-81673

The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. Th

CVE-2026-81674

The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized in

CVE-2026-81675

The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter.

CVE-2026-81676

A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenat

CVE-2026-81677

The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id

CVE-2026-81743

Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without res

CVE-2026-81753

Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing at

CVE-2026-81814

Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case

CVE-2026-26452

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segme

CVE-2026-26453

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_hand

CVE-2026-26456

A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c2

CVE-2026-26457

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg()

CVE-2026-26459

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmen

CVE-2026-26897

An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain

CVE-2026-26899

An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr

CVE-2026-30045

An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of

CVE-2026-30051

An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a

CVE-2026-30058

Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of

CVE-2026-30059

An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte

CVE-2026-30060

An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE

CVE-2026-30063

An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte

CVE-2026-30064

Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cau

CVE-2026-30067

An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to

CVE-2026-30068

Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers

CVE-2026-30069

A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Deni

CVE-2026-30070

An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a

CVE-2026-30071

An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted

CVE-2026-30072

A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (D

CVE-2026-30073

An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Se

CVE-2026-56651

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open

CVE-2026-56652

Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fai

CVE-2026-64896

Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functiona

CVE-2026-71401

An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/captu

CVE-2026-75357

An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili

CVE-2026-78251

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticate

CVE-2026-79653

In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage

CVE-2026-79718

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

CVE-2026-79719

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

CVE-2026-79720

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

CVE-2026-79988

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading t

CVE-2026-81817

Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue acr

CVE-2026-81818

Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authori

CVE-2026-81819

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint a

CVE-2026-81820

Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: *

CVE-2026-81826

Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m

CVE-2026-81827

Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That doe

CVE-2026-18885

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera

CVE-2026-18886

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th

CVE-2026-30612

An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <=

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started