Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 123/129
9.1
CVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val

9.1
CVE-2026-63687

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho

9.1
CVE-2026-65583

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che

9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses

9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru

9.1
CVE-2026-53976

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and

9.1
CVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati

9.1
CVE-2026-66709

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

9.1
CVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti

9.1
CVE-2026-53984

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit

9.1
CVE-2026-68823

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n

9.1
CVE-2026-16038

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or

9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0

9.1
CVE-2026-48039

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `A

9.1
CVE-2026-48170

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM

9.1
CVE-2026-18473

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in

9.1
CVE-2026-19053

The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQ

9.1
CVE-2026-72569

A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d

9.1
CVE-2026-72575

An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea

9.1
CVE-2026-68083

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_c

9.1
CVE-2026-68343

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed pa

9.1
CVE-2026-18412

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten

9.1
CVE-2026-44758

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted

9.1
CVE-2026-13716

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u

9.1
CVE-2026-19516

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf

9.1
CVE-2026-72748

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a

9.1
CVE-2026-73069

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad

9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before

9.1
CVE-2026-71362

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att

9.1
CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version

9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic

9.1
CVE-2026-67568

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int

9.1
CVE-2026-68431

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ

9.1
CVE-2026-16538

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top

9.1
CVE-2025-59324

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is

9.1
CVE-2026-73501

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/val

9.1
CVE-2026-59503

: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthoriz

9.1
CVE-2026-59504

: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (deve

9.1
CVE-2026-53791

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to

9.1
CVE-2022-4993

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca

9.1
CVE-2026-13051

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an

9.1
CVE-2026-55982

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

9.1
CVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

9.1
CVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

9.1
CVE-2026-58443

Public-only repository tokens can update private PR head branches

9.1
CVE-2026-58508

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

9.1
CVE-2026-73567

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0,

9.1
CVE-2026-19297

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

9.1
CVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with t

9.1
CVE-2026-49457

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the serve

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started