Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 165/454
8.1
CVE-2026-71239

DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const

8.1
CVE-2026-71285

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo

8.1
CVE-2026-15979

The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del

8.1
CVE-2026-15573

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security

8.1
CVE-2026-16102

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut

8.1
CVE-2026-39923

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t

8.1
CVE-2026-7327

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server

8.1
CVE-2026-8400

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a f

8.1
CVE-2026-70429

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistent

8.1
CVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic As

8.1
CVE-2026-66881

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with

8.1
CVE-2026-70617

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac

8.1
CVE-2026-18411

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k

8.1
CVE-2025-63822

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate

8.1
CVE-2026-71320

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject

8.1
CVE-2026-15459

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,

8.1
CVE-2026-57817

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th

8.1
CVE-2026-57818

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c

8.1
CVE-2026-65570

Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.

8.1
CVE-2026-66710

Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

8.1
CVE-2026-19111

Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Ag

8.1
CVE-2026-19153

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker

8.1
CVE-2026-43629

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path whe

8.1
CVE-2026-43631

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se

8.1
CVE-2026-43632

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to

8.1
CVE-2026-48081

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

8.1
CVE-2026-5857

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking

8.1
CVE-2026-64665

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was

8.1
CVE-2026-70634

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers

8.1
CVE-2026-15361

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n

8.1
CVE-2026-16030

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t

8.1
CVE-2026-16267

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from

8.1
CVE-2026-16948

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp

8.1
CVE-2026-17017

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in

8.1
CVE-2026-13600

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin

8.1
CVE-2026-18030

The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password

8.1
CVE-2026-18468

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc

8.1
CVE-2026-18469

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se

8.1
CVE-2026-66407

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket privat

8.1
CVE-2026-68100

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set

8.1
CVE-2026-68353

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in

8.1
CVE-2026-68373

In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x-usb: avoid length underflow in at76_

8.1
CVE-2026-68376

In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cook

8.1
CVE-2026-15467

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e

8.1
CVE-2026-72903

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu

8.1
CVE-2026-73030

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func

8.1
CVE-2026-15556

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th

8.1
CVE-2026-15560

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars

8.1
CVE-2026-72555

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.role

8.1
CVE-2026-72563

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started