Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1151/1152
CVE-2026-51656

Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac

CVE-2026-51657

Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack

CVE-2026-51658

Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

CVE-2026-51659

Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a

CVE-2026-51660

Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate

CVE-2026-54766

Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operati

CVE-2026-55068

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handle

CVE-2026-55220

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\

CVE-2026-55245

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in

CVE-2026-55378

JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow

CVE-2026-55509

WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgi

CVE-2026-55520

Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URL

CVE-2026-55673

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandEx

CVE-2026-22056

StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are su

CVE-2026-51661

Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated

CVE-2026-51662

Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica

CVE-2026-51663

Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at

CVE-2026-51664

Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack

CVE-2026-51665

Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at

CVE-2026-55678

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc

CVE-2026-55763

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfe

0.0
CVE-2026-55891

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequest

CVE-2026-75118

A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.2

CVE-2026-76649

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action request

CVE-2026-76650

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable

CVE-2026-76651

A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data

CVE-2026-55764

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role hold

CVE-2026-55867

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId

CVE-2026-10522

The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend

CVE-2026-80725

In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation cri

CVE-2026-82481

The cohttp package before 6.3.0 for OCaml allows directory traversal.

CVE-2026-75847

Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read acc

CVE-2026-77831

Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large arr

CVE-2026-77970

Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read acc

CVE-2026-75759

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impe

CVE-2026-77846

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attack

CVE-2026-14307

The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them

CVE-2026-14835

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custo

CVE-2026-19722

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files ext

CVE-2026-76585

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of custome

CVE-2026-78364

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting th

CVE-2026-81660

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape v

CVE-2026-81766

The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simp

CVE-2026-77454

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter

CVE-2026-78038

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban all

CVE-2026-78228

Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to

CVE-2026-78691

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who s

CVE-2026-80227

Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriag

CVE-2026-81316

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over

CVE-2026-81318

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application t

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started
Browse by year 2026