Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 170/454
8.1
CVE-2026-76331

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.1
CVE-2026-76338

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trus

8.1
CVE-2026-76354

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.1
CVE-2026-76356

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to a

8.1
CVE-2026-76387

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the

8.1
CVE-2026-76388

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role cou

8.1
CVE-2026-76397

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant

8.1
CVE-2026-76399

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled

8.1
CVE-2026-76886

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

8.1
CVE-2025-15637

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

8.1
CVE-2026-28150

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

8.1
CVE-2026-76633

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authentica

8.1
CVE-2026-63040

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati

8.1
CVE-2026-63042

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the

8.1
CVE-2026-77176

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection,

8.1
CVE-2026-76019

Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromise

8.1
CVE-2026-17000

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper au

8.1
CVE-2026-17060

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a

8.1
CVE-2026-17138

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas

8.1
CVE-2026-19437

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

8.1
CVE-2026-18781

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final na

8.1
CVE-2026-68745

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow

8.1
CVE-2026-39909

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows u

8.1
CVE-2026-64679

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 un

8.1
CVE-2026-18052

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which auth

8.1
CVE-2026-76793

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token

8.1
CVE-2026-74592

In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate ho

8.1
CVE-2026-74651

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie(

8.1
CVE-2026-28151

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

8.1
CVE-2026-28152

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

8.1
CVE-2026-66670

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

8.1
CVE-2026-66671

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

8.1
CVE-2026-39915

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP hea

8.1
CVE-2025-26237

D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b

8.1
CVE-2025-26238

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

8.1
CVE-2026-71504

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi

8.1
CVE-2026-71506

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al

8.1
CVE-2026-75464

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

8.1
CVE-2026-77567

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.

8.1
CVE-2026-34968

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop actio

8.1
CVE-2026-72695

Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated u

8.1
CVE-2026-78478

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes

8.1
CVE-2026-78562

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. T

8.1
CVE-2026-78566

The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This ma

8.1
CVE-2026-16231

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML esc

8.1
CVE-2026-78572

The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6

8.1
CVE-2026-78379

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.

8.1
CVE-2026-65081

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution

8.1
CVE-2026-65084

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper cer

8.1
CVE-2026-65098

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started