Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 195/1152
8.8
CVE-2026-62822

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

8.8
CVE-2026-62823

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo

8.8
CVE-2026-62824

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

8.8
CVE-2026-62827

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a networ

8.8
CVE-2026-62869

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over

8.8
CVE-2026-62872

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2026-62913

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

8.8
CVE-2026-63514

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-64901

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-64921

Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate pri

8.8
CVE-2026-65658

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65660

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t

8.8
CVE-2026-65663

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65665

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-65767

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allo

8.8
CVE-2026-65768

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an

8.8
CVE-2026-65807

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

8.8
CVE-2026-65811

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

8.8
CVE-2026-65815

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code

8.8
CVE-2026-66805

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-66808

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-69320

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows

8.8
CVE-2026-70321

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-70324

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov

8.8
CVE-2026-70326

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov

8.8
CVE-2026-70329

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ

8.8
CVE-2026-70336

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execu

8.8
CVE-2026-70337

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

8.8
CVE-2026-71386

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o

8.8
CVE-2026-71387

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the

8.8
CVE-2026-15426

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v

8.8
CVE-2026-18691

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc

8.8
CVE-2026-18692

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil

8.8
CVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio

8.8
CVE-2026-73224

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.8
CVE-2026-73226

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al

8.8
CVE-2026-14863

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at

8.8
CVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i

8.8
CVE-2026-55676

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P

8.8
CVE-2026-19556

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside

8.8
CVE-2026-19559

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi

8.8
CVE-2026-19560

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins

8.8
CVE-2026-5917

libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shel

8.8
CVE-2026-66875

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range

8.8
CVE-2026-68432

In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo

8.8
CVE-2026-13613

The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using

8.8
CVE-2026-11325

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository,

8.8
CVE-2026-73284

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi

8.8
CVE-2026-58076

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr

8.8
CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started