Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 171/454
8.1
CVE-2026-65105

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the

8.1
CVE-2026-78913

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar

8.1
CVE-2026-79020

Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory

8.1
CVE-2026-79027

Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code ins

8.1
CVE-2026-79039

Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar

8.1
CVE-2026-79057

Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social

8.1
CVE-2026-79072

Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall

8.1
CVE-2026-79194

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute

8.1
CVE-2026-79263

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code

8.1
CVE-2026-65183

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allow

8.1
CVE-2026-66422

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r

8.1
CVE-2026-68569

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that

8.1
CVE-2026-18985

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in

8.1
CVE-2026-58092

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was st

8.1
CVE-2026-80192

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) con

8.1
CVE-2026-19718

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before

8.1
CVE-2026-15985

The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all v

8.1
CVE-2026-75960

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. Thi

8.1
CVE-2026-81029

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLogin

8.1
CVE-2026-81035

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises th

8.1
CVE-2026-81036

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configu

8.1
CVE-2026-32257

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo

8.1
CVE-2026-32258

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.

8.1
CVE-2026-55228

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

8.1
CVE-2026-43621

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerabil

8.1
CVE-2026-77317

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evalu

8.1
CVE-2026-81273

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

8.1
CVE-2026-53580

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-downlo

8.1
CVE-2026-81522

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embed

8.1
CVE-2026-81525

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace ide

8.1
CVE-2026-81728

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with

8.1
CVE-2026-54083

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. T

8.1
CVE-2026-54330

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

8.1
CVE-2026-77977

Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive

8.1
CVE-2026-19423

The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve

8.1
CVE-2026-80599

In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: ensure accessible eth_hdr proto fi

8.1
CVE-2026-80645

In the Linux kernel, the following vulnerability has been resolved: rapidio/tsi721: prevent a bad dereference in tsi721

8.1
CVE-2026-82239

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowin

8.1
CVE-2026-82240

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoi

8.1
CVE-2026-82245

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authentic

8.1
CVE-2026-50979

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow

8.1
CVE-2026-55065

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:projec

8.1
CVE-2026-56100

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows a

8.1
CVE-2026-82269

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middl

8.1
CVE-2026-82279

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team membe

8.1
CVE-2026-82283

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users t

8.1
CVE-2026-82284

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id

8.1
CVE-2026-82287

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions b

8.1
CVE-2026-82291

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cros

8.1
CVE-2026-82461

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started