Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 166/454
8.1
CVE-2026-72595

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update tic

8.1
CVE-2026-72596

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete pos

8.1
CVE-2026-18129

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a

8.1
CVE-2026-72921

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth

8.1
CVE-2026-48440

ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in th

8.1
CVE-2026-62778

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

8.1
CVE-2026-62781

Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.

8.1
CVE-2026-62792

Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

8.1
CVE-2026-62819

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access

8.1
CVE-2026-62820

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an una

8.1
CVE-2026-62889

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a ne

8.1
CVE-2026-63520

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

8.1
CVE-2026-65679

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ

8.1
CVE-2026-65789

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

8.1
CVE-2026-65796

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ

8.1
CVE-2026-66802

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Att

8.1
CVE-2026-70340

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

8.1
CVE-2026-71331

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute cod

8.1
CVE-2026-18690

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag

8.1
CVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg

8.1
CVE-2026-73223

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.1
CVE-2026-73225

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.1
CVE-2026-73227

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.1
CVE-2026-18844

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (

8.1
CVE-2026-19091

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to

8.1
CVE-2026-18961

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera

8.1
CVE-2026-16977

The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is

8.1
CVE-2026-18057

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i

8.1
CVE-2026-18230

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta

8.1
CVE-2026-19594

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep

8.1
CVE-2026-70465

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.

8.1
CVE-2026-70468

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.

8.1
CVE-2026-47231

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c

8.1
CVE-2026-66375

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific

8.1
CVE-2026-73286

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a

8.1
CVE-2026-73289

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues:

8.1
CVE-2026-69105

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affe

8.1
CVE-2026-18098

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise

8.1
CVE-2026-18499

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using

8.1
CVE-2026-16904

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper p

8.1
CVE-2026-18952

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow

8.1
CVE-2026-19311

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remot

8.1
CVE-2026-12359

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

8.1
CVE-2026-13267

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

8.1
CVE-2026-19002

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can resu

8.1
CVE-2026-19004

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output pa

8.1
CVE-2026-73612

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete op

8.1
CVE-2026-73620

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing

8.1
CVE-2026-73624

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fail

8.1
CVE-2026-14668

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started