Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 190/436
5.9
CVE-2025-15631

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al

5.9
CVE-2026-48061

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa

5.9
CVE-2026-58042

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec

5.9
CVE-2026-16547

The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en

5.9
CVE-2026-48154

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri

5.9
CVE-2026-70599

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,

5.9
CVE-2026-70605

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,

5.9
CVE-2026-70606

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6

5.9
CVE-2026-10547

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id

5.9
CVE-2026-71310

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1

5.9
CVE-2024-6832

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta

5.9
CVE-2026-66732

Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe

5.9
CVE-2026-28179

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.

5.9
CVE-2026-66706

Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.

5.9
CVE-2026-70637

LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause un

5.9
CVE-2026-11361

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme

5.9
CVE-2026-12901

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications,

5.9
CVE-2026-15211

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal

5.9
CVE-2026-37171

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one

5.9
CVE-2026-49343

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie

5.9
CVE-2026-72917

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

5.9
CVE-2026-58237

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l

5.9
CVE-2026-58238

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could

5.9
CVE-2026-66773

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i

5.9
CVE-2026-66776

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec

5.9
CVE-2026-66777

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D

5.9
CVE-2026-11893

The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo

5.9
CVE-2026-11894

The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the

5.9
CVE-2026-6181

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after

5.9
CVE-2026-6727

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a

5.9
CVE-2026-73068

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI

5.9
CVE-2026-62899

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker

5.9
CVE-2026-62900

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose

5.9
CVE-2026-68819

Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

5.9
CVE-2026-12233

The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre

5.9
CVE-2026-18663

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess

5.9
CVE-2026-69107

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

5.9
CVE-2026-19642

An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authentica

5.9
CVE-2026-73344

Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

5.9
CVE-2026-53801

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows

5.9
CVE-2026-57886

Cross-repository issue/comment attachment re-linking can expose private attachment content

5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti

5.9
CVE-2026-56860

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer

5.9
CVE-2026-16739

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request

5.9
CVE-2026-74244

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker

5.9
CVE-2026-74245

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could downloa

5.9
CVE-2026-13700

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request a

5.9
CVE-2026-68762

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

5.9
CVE-2026-45791

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/

5.9
CVE-2026-65329

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started