Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 177/436
6.1
CVE-2026-73898

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.1
CVE-2026-66358

A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.

6.1
CVE-2026-75900

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the

6.1
CVE-2026-75148

cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_valid

6.1
CVE-2026-40507

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handl

6.1
CVE-2026-20302

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to

6.1
CVE-2026-55087

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path

6.1
CVE-2026-67189

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffi

6.1
CVE-2026-71368

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected

6.1
CVE-2026-54770

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob

6.1
CVE-2026-69234

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allo

6.1
CVE-2026-69235

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,

6.1
CVE-2026-69236

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote,

6.1
CVE-2026-68767

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an inpu

6.1
CVE-2026-68768

hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. Wh

6.1
CVE-2026-5389

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializ

6.1
CVE-2026-5751

justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability

6.1
CVE-2026-6827

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling.

6.1
CVE-2026-74793

justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler

6.1
CVE-2026-77088

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code s

6.1
CVE-2026-8630

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the seriali

6.1
CVE-2026-19852

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers

6.1
CVE-2026-65053

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without esca

6.1
CVE-2026-78475

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin al

6.1
CVE-2026-71503

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration templa

6.1
CVE-2022-30983

A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows rem

6.1
CVE-2026-55059

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.1
CVE-2026-56704

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without

6.1
CVE-2026-17089

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S

6.1
CVE-2026-75038

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This is

6.1
CVE-2026-55530

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval d

6.1
CVE-2026-13216

The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization.

6.1
CVE-2026-16638

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folde

6.1
CVE-2026-16640

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API

6.1
CVE-2026-47848

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client

6.1
CVE-2026-39275

Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code

6.1
CVE-2026-47883

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue ap

6.1
CVE-2026-47887

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a con

6.1
CVE-2026-59355

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validat

6.1
CVE-2026-11747

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syW

6.1
CVE-2026-19854

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connecti

6.1
CVE-2026-5738

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatic

6.1
CVE-2026-81334

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's

6.1
CVE-2026-59281

Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then rende

6.1
CVE-2026-4246

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advan

6.1
CVE-2026-37710

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site na

6.1
CVE-2026-5800

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software I

6.1
CVE-2026-5953

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics

6.1
CVE-2026-82324

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the

6.1
CVE-2026-82328

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started