Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 150/436
6.2
CVE-2026-71204

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into

6.2
CVE-2026-71293

Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f

6.2
CVE-2026-71430

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function

6.2
CVE-2026-18938

A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a

6.2
CVE-2026-72522

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same

6.2
CVE-2026-72744

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the

6.2
CVE-2026-72783

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne

6.2
CVE-2026-17535

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by

6.2
CVE-2026-48387

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati

6.2
CVE-2026-48434

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

6.2
CVE-2026-48435

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a

6.2
CVE-2026-48443

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

6.2
CVE-2026-48444

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati

6.2
CVE-2026-48445

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati

6.2
CVE-2026-71389

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a

6.2
CVE-2026-56657

Gitea SSH Key Parser Denial of Service

6.2
CVE-2026-56755

Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

6.2
CVE-2026-73047

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view

6.2
CVE-2026-49301

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect

6.2
CVE-2026-49302

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerabili

6.2
CVE-2026-49304

Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerabil

6.2
CVE-2026-49305

Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability

6.2
CVE-2026-49307

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability m

6.2
CVE-2026-74871

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st

6.2
CVE-2026-75057

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

6.2
CVE-2026-44846

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a us

6.2
CVE-2026-18874

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Anothe

6.2
CVE-2026-53762

VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created

6.2
CVE-2026-70626

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to

6.2
CVE-2026-71832

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote

6.2
CVE-2026-55373

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.2
CVE-2026-71444

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a

6.2
CVE-2026-76189

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a

6.2
CVE-2026-81682

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes

6.2
CVE-2026-81684

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to

6.2
CVE-2026-81686

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set m

6.2
CVE-2026-81720

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing

6.2
CVE-2026-3686

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limi

6.1
CVE-2025-13153

The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting

6.1
CVE-2025-13456

The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the

6.1
CVE-2025-45286

A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script

6.1
CVE-2025-62857

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit th

6.1
CVE-2026-21487

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below

6.1
CVE-2026-21488

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below

6.1
CVE-2026-21489

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below

6.1
CVE-2020-36924

Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitra

6.1
CVE-2025-63082

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

6.1
CVE-2025-63083

Lack of output escaping leads to a XSS vector in the pagebreak plugin.

6.1
CVE-2026-21490

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

6.1
CVE-2026-21491

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started