Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 164/454
8.1
CVE-2026-67595

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re

8.1
CVE-2026-17686

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke

8.1
CVE-2026-17869

Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bound

8.1
CVE-2026-17995

Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds

8.1
CVE-2026-18186

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr

8.1
CVE-2026-18187

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control

8.1
CVE-2026-18188

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled

8.1
CVE-2026-67245

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled

8.1
CVE-2026-56428

The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly

8.1
CVE-2026-67345

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in Defaul

8.1
CVE-2026-67348

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authe

8.1
CVE-2026-15658

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t

8.1
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all

8.1
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten

8.1
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr

8.1
CVE-2026-13444

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin

8.1
CVE-2026-63035

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack

8.1
CVE-2026-12251

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m

8.1
CVE-2026-12695

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted

8.1
CVE-2026-15258

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe

8.1
CVE-2026-65313

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c

8.1
CVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend

8.1
CVE-2026-53510

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL

8.1
CVE-2026-14309

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been

8.1
CVE-2026-14836

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset

8.1
CVE-2026-15368

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after use

8.1
CVE-2026-15450

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path trav

8.1
CVE-2026-16144

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all

8.1
CVE-2026-67328

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling

8.1
CVE-2026-12586

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset

8.1
CVE-2026-68581

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and

8.1
CVE-2026-18577 KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu

8.1
CVE-2026-20465

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro

8.1
CVE-2025-15672

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa

8.1
CVE-2026-16539

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S

8.1
CVE-2026-18092

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm

8.1
CVE-2026-69088

Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint

8.1
CVE-2026-67610

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi

8.1
CVE-2026-67611

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci

8.1
CVE-2026-52521

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th

8.1
CVE-2026-66318

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

8.1
CVE-2026-24079

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

8.1
CVE-2026-18830

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co

8.1
CVE-2026-70482

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB

8.1
CVE-2026-70494

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE

8.1
CVE-2026-14553

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte

8.1
CVE-2026-15230

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, rely

8.1
CVE-2026-54418

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable,

8.1
CVE-2026-7444

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and

8.1
CVE-2026-7520

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started