Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 189/436
5.9
CVE-2026-60610

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The

5.9
CVE-2026-60669

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Pay

5.9
CVE-2026-60695

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operatio

5.9
CVE-2026-60801

Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).

5.9
CVE-2026-61069

Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General

5.9
CVE-2026-61103

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The

5.9
CVE-2026-62484

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

5.9
CVE-2026-13188

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potential

5.9
CVE-2026-14586

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under

5.9
CVE-2026-44621

With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-

5.9
CVE-2026-50046

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queri

5.9
CVE-2026-52863

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together

5.9
CVE-2026-55717

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip:

5.9
CVE-2026-55990

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:'

5.9
CVE-2026-55991

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 asserti

5.9
CVE-2026-56444

In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve

5.9
CVE-2025-68081

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

5.9
CVE-2026-24628

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

5.9
CVE-2026-65483

Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.

5.9
CVE-2026-65534

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

5.9
CVE-2026-65538

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

5.9
CVE-2026-65550

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

5.9
CVE-2026-66053

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect

5.9
CVE-2026-65557

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

5.9
CVE-2026-65563

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

5.9
CVE-2026-66475

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versi

5.9
CVE-2024-14041

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno

5.9
CVE-2026-66754

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that all

5.9
CVE-2026-16107

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validat

5.9
CVE-2026-33930

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handl

5.9
CVE-2026-58152

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apa

5.9
CVE-2026-58158

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects A

5.9
CVE-2026-58183

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach

5.9
CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 t

5.9
CVE-2026-67213

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun

5.9
CVE-2026-67214

nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no

5.9
CVE-2026-67216

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the

5.9
CVE-2026-50558

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d

5.9
CVE-2026-14643

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva

5.9
CVE-2026-11782

The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a w

5.9
CVE-2026-16971

The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a

5.9
CVE-2026-18362

The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo

5.9
CVE-2026-63362

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau

5.9
CVE-2026-67607

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr

5.9
CVE-2026-67294

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si

5.9
CVE-2026-67354

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the

5.9
CVE-2026-67355

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain

5.9
CVE-2025-71401

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B

5.9
CVE-2025-15544

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assoc

5.9
CVE-2025-15630

A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started