Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 17/436
6.6
CVE-2026-16062

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co

6.6
CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.

6.6
CVE-2026-40717

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera

6.6
CVE-2026-47619

NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A s

6.6
CVE-2026-70593

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff

6.6
CVE-2026-70602

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,

6.6
CVE-2026-11743

The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o

6.6
CVE-2026-61920

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut

6.6
CVE-2026-18706

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation

6.6
CVE-2026-68756

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

6.6
CVE-2026-73330

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to ex

6.6
CVE-2026-73433

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_

6.6
CVE-2026-19696

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

6.6
CVE-2026-73583

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnera

6.6
CVE-2026-10035

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

6.6
CVE-2026-19976

A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /

6.6
CVE-2026-65349

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,

6.6
CVE-2026-62475

Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Sup

6.6
CVE-2026-70888

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu

6.6
CVE-2026-56796

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Follow

6.6
CVE-2026-76372

In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR co

6.6
CVE-2026-13405

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before

6.6
CVE-2026-66586

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

6.6
CVE-2025-62299

HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces

6.6
CVE-2026-44725

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3,

6.6
CVE-2026-18273

Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows

6.6
CVE-2026-55586

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffm

6.6
CVE-2026-19222

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to

6.6
CVE-2026-77988

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of th

6.6
CVE-2026-62204

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install

6.6
CVE-2026-62381

luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.

6.6
CVE-2026-63693

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile

6.6
CVE-2026-14280

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion i

6.6
CVE-2026-18444

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered

6.6
CVE-2026-18445

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This

6.6
CVE-2026-19225

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators,

6.6
CVE-2026-59275

A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu

6.6
CVE-2026-59293

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks m

6.6
CVE-2026-55569

aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the hand

6.6
CVE-2026-76547

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor

6.5
CVE-2025-48768

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX

6.5
CVE-2025-12685

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica

6.5
CVE-2025-44013

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-47208

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating

6.5
CVE-2025-53591

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver

6.5
CVE-2025-53592

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-53593

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-48721

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-52871

An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user accoun

6.5
CVE-2025-53597

A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started