Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 171/436
6.1
CVE-2026-58520

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E

6.1
CVE-2026-14358

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun

6.1
CVE-2025-71385

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi

6.1
CVE-2026-58381

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe

6.1
CVE-2026-4322

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web

6.1
CVE-2026-25779

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect

6.1
CVE-2026-58291

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

6.1
CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back

6.1
CVE-2026-50133

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to

6.1
CVE-2026-59711

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr

6.1
CVE-2026-59710

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta

6.1
CVE-2026-7380

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno

6.1
CVE-2026-8306

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information

6.1
CVE-2026-53878

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin

6.1
CVE-2026-48949

Lack of validation leads to an XSS vulnerability in the MFA management views.

6.1
CVE-2026-48950

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

6.1
CVE-2026-48951

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

6.1
CVE-2026-48952

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

6.1
CVE-2026-48953

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

6.1
CVE-2026-48954

Improper validation leads to a generic XSS vector in the language override feature.

6.1
CVE-2026-11798

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle

6.1
CVE-2026-57241

The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related

6.1
CVE-2026-57243

During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat

6.1
CVE-2026-57253

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in

6.1
CVE-2026-57255

The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo

6.1
CVE-2026-57257

During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o

6.1
CVE-2026-57258

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl

6.1
CVE-2026-8310

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig

6.1
CVE-2026-60092

AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vuln

6.1
CVE-2026-59890

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to

6.1
CVE-2026-59895

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in

6.1
CVE-2026-59923

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p

6.1
CVE-2026-59926

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc

6.1
CVE-2026-59929

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende

6.1
CVE-2026-50813

An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the S

6.1
CVE-2026-59946

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containi

6.1
CVE-2026-55877

Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T

6.1
CVE-2026-15127

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit

6.1
CVE-2026-15128

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit

6.1
CVE-2026-13334

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v

6.1
CVE-2026-5793

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an

6.1
CVE-2026-58303

Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E

6.1
CVE-2026-58304

Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss

6.1
CVE-2026-58305

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point

6.1
CVE-2026-58306

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es

6.1
CVE-2026-58307

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat

6.1
CVE-2026-0279

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, Global

6.1
CVE-2026-55590

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior

6.1
CVE-2026-11392

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'c

6.1
CVE-2026-15297

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started