Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 16/42
3.5
CVE-2026-19230

A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci

3.5
CVE-2026-73281

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi

3.5
CVE-2026-64951

A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic

3.5
CVE-2026-19916

A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function

3.5
CVE-2026-19922

A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown

3.5
CVE-2026-19955

A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component T

3.5
CVE-2026-19995

A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account

3.5
CVE-2026-70412

Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readab

3.5
CVE-2026-9693

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a us

3.5
CVE-2026-45126

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate t

3.5
CVE-2026-45127

MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain request

3.5
CVE-2026-45128

MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate reques

3.5
CVE-2026-62529

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

3.5
CVE-2026-75583

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerab

3.5
CVE-2026-18102

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer

3.5
CVE-2026-18278

Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows

3.5
CVE-2026-14325

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its set

3.5
CVE-2026-69238

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly

3.5
CVE-2026-33333

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the

3.5
CVE-2026-76816

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final,

3.5
CVE-2026-70548

Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External De

3.5
CVE-2026-7487

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3

3.5
CVE-2026-56547

The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler

3.5
CVE-2026-77508

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email

3.5
CVE-2026-77573

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

3.5
CVE-2026-13416

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming

3.5
CVE-2026-81717

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, wh

3.5
CVE-2026-81848

A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fe

3.5
CVE-2026-82112

A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src

3.5
CVE-2026-82482

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an

3.5
CVE-2026-82483

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown functi

3.5
CVE-2026-82488

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component Us

3.4
CVE-2025-69412

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phi

3.4
CVE-2026-0519

In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u

3.4
CVE-2026-23686

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr

3.4
CVE-2026-21422

Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setti

3.4
CVE-2025-68467

Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the

3.4
CVE-2026-32772

telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON

3.4
CVE-2025-62184

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf

3.4
CVE-2026-33404

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic

3.4
CVE-2026-35361

The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting

3.4
CVE-2026-44405

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

3.4
CVE-2026-42195

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts

3.4
CVE-2026-40131

SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user

3.4
CVE-2026-34685

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an

3.4
CVE-2026-49370

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

3.4
CVE-2026-49381

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

3.4
CVE-2026-9062

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h

3.4
CVE-2026-48940

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field

3.4
CVE-2025-62675

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started