Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 126/129
9.1
CVE-2026-71933

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul

9.1
CVE-2026-76835

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b

9.1
CVE-2026-59769

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel'

9.1
CVE-2026-55976

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated r

9.1
CVE-2026-55536

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome ex

9.1
CVE-2026-55640

Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11

9.1
CVE-2026-79058

Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

9.1
CVE-2026-79148

Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social enginee

9.1
CVE-2026-65182

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a

9.1
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security

9.1
CVE-2026-78655

Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earli

9.1
CVE-2026-16644

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST v

9.1
CVE-2026-16645

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Bro

9.1
CVE-2026-59682

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

9.1
CVE-2026-77535

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

9.1
CVE-2026-77539

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

9.1
CVE-2026-77540

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

9.1
CVE-2026-77541

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability

9.1
CVE-2026-77542

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

9.1
CVE-2026-75896

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows

9.1
CVE-2026-70419

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an

9.1
CVE-2025-51679

An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected

9.1
CVE-2026-75332

Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

9.1
CVE-2026-75340

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is

9.1
CVE-2026-78274

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

9.1
CVE-2026-57499

Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log

9.1
CVE-2026-81094

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked

9.1
CVE-2026-81098

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc

9.1
CVE-2026-59283

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable

9.1
CVE-2026-50152

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

9.1
CVE-2026-61800

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

9.1
CVE-2026-80603

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by

9.1
CVE-2026-80670

In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in mac

9.1
CVE-2026-42007

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free

9.1
CVE-2026-82244

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticat

9.1
CVE-2026-55247

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in sr

9.1
CVE-2026-55248

plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and

9.1
CVE-2026-55511

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiv

9.1
CVE-2026-3627

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL state

9.1
CVE-2026-16947

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path b

9.1
CVE-2026-82454

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in toke

9.1
CVE-2026-82539

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of t

9.0
CVE-2025-59468

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending

9.0
CVE-2025-59469

This vulnerability allows a Backup or Tape Operator to write files as root.

9.0
CVE-2025-59470

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal

9.0
CVE-2025-12548

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe

9.0
CVE-2026-23520

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane

9.0
CVE-2026-1009

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitizati

9.0
CVE-2026-1181

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy tha

9.0
CVE-2026-23873

hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vuln

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started