Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 192/1152
8.8
CVE-2026-18598

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l

8.8
CVE-2026-18600

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s

8.8
CVE-2026-69096

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after

8.8
CVE-2026-18607

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53

8.8
CVE-2026-41453

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use

8.8
CVE-2026-18733

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors

8.8
CVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

8.8
CVE-2026-64561

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m

8.8
CVE-2026-64562

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr

8.8
CVE-2026-70369

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con

8.8
CVE-2026-70370

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu

8.8
CVE-2026-70371

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request

8.8
CVE-2026-70372

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa

8.8
CVE-2026-70373

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc

8.8
CVE-2026-17070

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b

8.8
CVE-2026-18650

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY

8.8
CVE-2026-67195

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr

8.8
CVE-2026-69100

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i

8.8
CVE-2026-15307

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse

8.8
CVE-2026-18787

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi

8.8
CVE-2026-16793

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo

8.8
CVE-2026-70619

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users

8.8
CVE-2026-18895

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /go

8.8
CVE-2026-18897

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strc

8.8
CVE-2026-18898

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the fil

8.8
CVE-2026-18322

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu

8.8
CVE-2026-8761

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i

8.8
CVE-2026-70374

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail genera

8.8
CVE-2026-70375

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe

8.8
CVE-2026-55997

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token

8.8
CVE-2026-6147

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th

8.8
CVE-2026-60009

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every

8.8
CVE-2026-71235

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid

8.8
CVE-2026-71243

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest

8.8
CVE-2026-71281

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src

8.8
CVE-2026-71287

Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because

8.8
CVE-2026-71288

Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name

8.8
CVE-2026-71291

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe

8.8
CVE-2026-67623

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com

8.8
CVE-2026-15572

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe

8.8
CVE-2026-17623

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to i

8.8
CVE-2026-17626

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv

8.8
CVE-2026-20200

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with lo

8.8
CVE-2026-20312

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t

8.8
CVE-2026-70431

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Sc

8.8
CVE-2026-70432

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows atta

8.8
CVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to impro

8.8
CVE-2026-8182

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server

8.8
CVE-2026-8478

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i

8.8
CVE-2026-9201

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started