Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 176/454
8.0
CVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v

8.0
CVE-2026-11766

The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea p

8.0
CVE-2025-53829

ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack

8.0
CVE-2026-34171

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

8.0
CVE-2026-14476

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz

8.0
CVE-2026-11903

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr

8.0
CVE-2026-59224

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu

8.0
CVE-2026-15293

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

8.0
CVE-2026-40400

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

8.0
CVE-2026-42975

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja

8.0
CVE-2026-49169

Use after free in DNS Server allows an authorized attacker to execute code over a network.

8.0
CVE-2026-58647

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized at

8.0
CVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ

8.0
CVE-2026-50502

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute cod

8.0
CVE-2026-50683

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n

8.0
CVE-2026-62215

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo

8.0
CVE-2026-45162

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc

8.0
CVE-2025-71392

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the

8.0
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using

8.0
CVE-2026-21575

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and

8.0
CVE-2026-47237

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio

8.0
CVE-2026-46923

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth

8.0
CVE-2026-60325

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

8.0
CVE-2026-60533

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Conn

8.0
CVE-2026-60579

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).

8.0
CVE-2026-60643

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.0
CVE-2026-60646

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-60648

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-60650

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-60652

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-60790

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supporte

8.0
CVE-2026-60807

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp

8.0
CVE-2026-61009

Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Oper

8.0
CVE-2026-61067

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

8.0
CVE-2026-61224

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Sec

8.0
CVE-2026-63265

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension

8.0
CVE-2026-60371

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.0
CVE-2026-35425

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

8.0
CVE-2026-12736

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This

8.0
CVE-2026-64406

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accep

8.0
CVE-2026-59689

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio

8.0
CVE-2026-59690

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M

8.0
CVE-2026-12703

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti

8.0
CVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati

8.0
CVE-2026-47873

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network int

8.0
CVE-2026-9044

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an

8.0
CVE-2026-18599

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f

8.0
CVE-2026-16623

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g

8.0
CVE-2026-71279

Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa

8.0
CVE-2026-66297

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started