Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 191/436
5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string

5.9
CVE-2026-50139

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit

5.9
CVE-2026-52739

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placi

5.9
CVE-2026-70677

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

5.9
CVE-2026-70716

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

5.9
CVE-2026-70789

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

5.9
CVE-2026-71075

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

5.9
CVE-2026-73909

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

5.9
CVE-2026-27365

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Publi

5.9
CVE-2026-49870

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at

5.9
CVE-2026-16827

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use

5.9
CVE-2026-76320

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authentic

5.9
CVE-2026-76393

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe

5.9
CVE-2026-76400

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

5.9
CVE-2026-76401

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

5.9
CVE-2026-76956

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w

5.9
CVE-2026-66595

Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

5.9
CVE-2025-62300

HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can

5.9
CVE-2026-55558

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib

5.9
CVE-2026-75514

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and ant

5.9
CVE-2026-77587

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg rev

5.9
CVE-2026-49244

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP

5.9
CVE-2026-59296

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a danger

5.9
CVE-2026-76876

Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sens

5.9
CVE-2026-53572

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constru

5.9
CVE-2026-69224

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff

5.9
CVE-2026-69225

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that m

5.9
CVE-2026-62385

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all

5.9
CVE-2026-59295

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) cond

5.9
CVE-2026-79652

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat

5.9
CVE-2026-63074

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a C

5.9
CVE-2026-79676

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin

5.9
CVE-2026-79785

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto

5.9
CVE-2026-13217

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLR

5.9
CVE-2026-79013

Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.9
CVE-2026-79122

Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa

5.9
CVE-2026-79126

Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an

5.9
CVE-2026-79208

Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive infor

5.9
CVE-2026-80206

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep

5.9
CVE-2026-32593

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

5.9
CVE-2026-79940

Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con

5.9
CVE-2026-74774

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe

5.9
CVE-2026-47857

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a

5.9
CVE-2026-47863

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a

5.9
CVE-2026-47881

Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp

5.9
CVE-2026-76549

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its bac

5.9
CVE-2026-75159

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m

5.9
CVE-2026-80211

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_

5.9
CVE-2026-59276

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())

5.9
CVE-2026-59294

ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started