Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 195/436
5.8
CVE-2026-17890

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

5.8
CVE-2026-17891

Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised

5.8
CVE-2026-17893

Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote at

5.8
CVE-2026-17906

Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacke

5.8
CVE-2026-17908

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remo

5.8
CVE-2026-18369

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns

5.8
CVE-2026-10686

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing

5.8
CVE-2026-68585

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r

5.8
CVE-2026-10526

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th

5.8
CVE-2026-48071

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.8
CVE-2026-16949

The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL

5.8
CVE-2026-71959

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c

5.8
CVE-2026-73243

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add

5.8
CVE-2026-72788

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to prope

5.8
CVE-2026-72790

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that

5.8
CVE-2026-72791

SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information d

5.8
CVE-2026-72792

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag l

5.8
CVE-2026-72796

SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass p

5.8
CVE-2026-72797

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint

5.8
CVE-2026-72799

SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoi

5.8
CVE-2026-72800

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing

5.8
CVE-2026-72803

SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoint

5.8
CVE-2026-72805

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeI

5.8
CVE-2026-72806

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter tha

5.8
CVE-2026-72808

SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api

5.8
CVE-2026-19130

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific

5.8
CVE-2026-73605

SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anony

5.8
CVE-2026-73606

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that

5.8
CVE-2026-73607

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endp

5.8
CVE-2026-73609

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that ret

5.8
CVE-2026-73610

SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the admin

5.8
CVE-2026-73048

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoin

5.8
CVE-2026-73049

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint

5.8
CVE-2026-73630

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoin

5.8
CVE-2026-12365

A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work tim

5.8
CVE-2026-73058

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthe

5.8
CVE-2026-75000

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attrib

5.8
CVE-2026-75003

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image coul

5.8
CVE-2026-75006

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTM

5.8
CVE-2026-48053

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalid

5.8
CVE-2026-75145

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/r

5.8
CVE-2026-50550

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmi

5.8
CVE-2026-72861

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. ver

5.8
CVE-2026-74866

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only o

5.8
CVE-2026-78205

BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link

5.8
CVE-2026-34964

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, wh

5.8
CVE-2026-79939

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerabilit

5.8
CVE-2026-82477

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal netw

5.7
CVE-2025-59955

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri

5.7
CVE-2025-68158

Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started