Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 129/454
8.2
CVE-2026-56672

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control

8.2
CVE-2026-18141

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthentic

8.2
CVE-2026-53500

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes

8.2
CVE-2026-53501

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasse

8.2
CVE-2026-14920

## Summary

8.2
CVE-2026-15055

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a

8.2
CVE-2026-10849

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser

8.2
CVE-2026-58080

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On

8.2
CVE-2026-24253

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful expl

8.2
CVE-2026-47623

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ

8.2
CVE-2026-70486

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi

8.2
CVE-2026-64578

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin

8.2
CVE-2026-6627

The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a

8.2
CVE-2026-71252

toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands,

8.2
CVE-2026-71264

WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike

8.2
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec

8.2
CVE-2026-71315

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules

8.2
CVE-2026-14829

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr

8.2
CVE-2026-16268

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi

8.2
CVE-2026-66708

Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

8.2
CVE-2026-66838

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr

8.2
CVE-2026-16257

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh

8.2
CVE-2026-12984

Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T

8.2
CVE-2026-68118

In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVE

8.2
CVE-2026-14886

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma

8.2
CVE-2026-72922

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

8.2
CVE-2026-21279

is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker co

8.2
CVE-2026-69306

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature

8.2
CVE-2026-48771

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed du

8.2
CVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath

8.2
CVE-2026-48763

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t

8.2
CVE-2026-6484

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

8.2
CVE-2026-64954

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th

8.2
CVE-2026-13171

The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han

8.2
CVE-2026-19426

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl

8.2
CVE-2026-17445

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

8.2
CVE-2026-73303

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a cli

8.2
CVE-2026-10543

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted

8.2
CVE-2026-17485

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information

8.2
CVE-2026-18945

The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confir

8.2
CVE-2026-59501

: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)

8.2
CVE-2026-73613

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction

8.2
CVE-2026-14679

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p

8.2
CVE-2026-70456

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicio

8.2
CVE-2026-70458

rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by trigge

8.2
CVE-2026-70461

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers

8.2
CVE-2026-13048

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra

8.2
CVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metada

8.2
CVE-2026-73650

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version

8.2
CVE-2026-17272

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started