Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 129/129
9.0
CVE-2026-48327

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the

9.0
CVE-2026-62378

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS C

9.0
CVE-2026-11386

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).

9.0
CVE-2026-64106

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-

9.0
CVE-2026-12701

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa

9.0
CVE-2026-35198

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i

9.0
CVE-2026-60249

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

9.0
CVE-2026-60424

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

9.0
CVE-2026-61174

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

9.0
CVE-2026-61201

Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects).

9.0
CVE-2026-61204

Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Int

9.0
CVE-2026-61223

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Sec

9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable

9.0
CVE-2026-14289

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request hand

9.0
CVE-2026-14602

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, al

9.0
CVE-2026-18245

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic

9.0
CVE-2026-17351

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu

9.0
CVE-2026-10090

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl

9.0
CVE-2026-20267

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

9.0
CVE-2026-70426

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2

9.0
CVE-2025-14561

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o

9.0
CVE-2026-71851

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt

9.0
CVE-2026-48381

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL

9.0
CVE-2026-71471

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically wit

9.0
CVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal

9.0
CVE-2026-72279

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping

9.0
CVE-2026-73041

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp

9.0
CVE-2026-73042

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to ex

9.0
CVE-2026-73043

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which

9.0
CVE-2026-73044

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting

9.0
CVE-2026-73050

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stor

9.0
CVE-2026-73052

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option

9.0
CVE-2026-73053

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to s

9.0
CVE-2026-74800

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file ass

9.0
CVE-2026-14564

Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co.

9.0
CVE-2026-75130

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions

9.0
CVE-2026-75625

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to t

9.0
CVE-2026-61029

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

9.0
CVE-2026-62988

Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Adm

9.0
CVE-2026-70980

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

9.0
CVE-2026-18937

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input o

9.0
CVE-2026-72530 KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4

9.0
CVE-2026-32475

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.

9.0
CVE-2026-62674

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /ses

9.0
CVE-2026-77545

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug

9.0
CVE-2026-77549

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CR

9.0
CVE-2026-77551

A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulne

9.0
CVE-2026-40541

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started
Browse by year 2026