Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 169/436
6.1
CVE-2026-45500

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

6.1
CVE-2026-47991

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redire

6.1
CVE-2026-36725

A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 a

6.1
CVE-2026-32856

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerab

6.1
CVE-2026-34416

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit

6.1
CVE-2026-25860

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al

6.1
CVE-2026-34417

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit

6.1
CVE-2026-41008

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame

6.1
CVE-2026-41706

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser

6.1
CVE-2026-49496

Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator

6.1
CVE-2026-45560

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wr

6.1
CVE-2026-45566

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th

6.1
CVE-2026-46642

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file ca

6.1
CVE-2026-45384

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4

6.1
CVE-2026-53737

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page.

6.1
CVE-2026-47250

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the

6.1
CVE-2026-50089

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire

6.1
CVE-2026-41568

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and

6.1
CVE-2026-49294

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and

6.1
CVE-2026-36521

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

6.1
CVE-2026-37216

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

6.1
CVE-2026-48157

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.

6.1
CVE-2026-53841

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe j

6.1
CVE-2026-12425

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool

6.1
CVE-2026-46770

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Secu

6.1
CVE-2026-46812

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

6.1
CVE-2026-12459

Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbi

6.1
CVE-2026-54386

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti

6.1
CVE-2026-44644

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are

6.1
CVE-2026-12137

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is

6.1
CVE-2026-47833

setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp

6.1
CVE-2026-44663

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.1
CVE-2026-44915

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au

6.1
CVE-2025-71331

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat

6.1
CVE-2026-56317

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo

6.1
CVE-2026-56347

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering d

6.1
CVE-2026-56236

Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations th

6.1
CVE-2026-4110

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp

6.1
CVE-2026-12479

A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method

6.1
CVE-2026-50557

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-52725

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-54264

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-54265

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-54266

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-54267

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script

6.1
CVE-2026-46417

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-50169

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-50171

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-50184

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started