Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 173/436
6.1
CVE-2026-57896

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti

6.1
CVE-2026-58643

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u

6.1
CVE-2026-11324

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros

6.1
CVE-2026-15094

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame

6.1
CVE-2026-10525

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and

6.1
CVE-2026-51081

A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environmen

6.1
CVE-2026-49210

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child

6.1
CVE-2026-54243

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission valu

6.1
CVE-2026-2445

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod

6.1
CVE-2026-32822

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

6.1
CVE-2026-58413

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b

6.1
CVE-2026-26483

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template managemen

6.1
CVE-2026-44227

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contai

6.1
CVE-2026-61901

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an

6.1
CVE-2026-44230

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10

6.1
CVE-2026-47128

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc

6.1
CVE-2026-51025

Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary

6.1
CVE-2023-37508

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v

6.1
CVE-2026-8284

URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data

6.1
CVE-2026-47121

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `re

6.1
CVE-2026-47714

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code i

6.1
CVE-2026-52475

Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the

6.1
CVE-2026-34316

Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). T

6.1
CVE-2026-47002

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framewo

6.1
CVE-2026-47178

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (unco

6.1
CVE-2026-47251

libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) intro

6.1
CVE-2026-47254

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()`

6.1
CVE-2026-60146

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

6.1
CVE-2026-60161

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

6.1
CVE-2026-60162

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

6.1
CVE-2026-60608

Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Metho

6.1
CVE-2026-60685

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver

6.1
CVE-2026-60802

Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-60815

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th

6.1
CVE-2026-60842

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported vers

6.1
CVE-2026-61220

Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configurat

6.1
CVE-2026-62444

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-62487

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-62505

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

6.1
CVE-2026-64828

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac

6.1
CVE-2026-9066

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse

6.1
CVE-2026-65756

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr

6.1
CVE-2026-65899

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPuri

6.1
CVE-2026-65900

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RE

6.1
CVE-2026-65901

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled n

6.1
CVE-2026-65902

DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS an

6.1
CVE-2026-65903

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden t

6.1
CVE-2026-65911

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int

6.1
CVE-2026-65912

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function

6.1
CVE-2026-65913

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started