Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 2/42
3.8
CVE-2026-3470

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to dat

3.8
CVE-2026-22014

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events)

3.8
CVE-2026-31051

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Ba

3.8
CVE-2026-44987

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissi

3.8
CVE-2026-34094

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Art

3.8
CVE-2026-44459

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat

3.8
CVE-2026-33585

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke

3.8
CVE-2026-6923

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie

3.8
CVE-2026-3495

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious con

3.8
CVE-2026-44410

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended

3.8
CVE-2026-6816

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or

3.8
CVE-2026-40510

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history

3.8
CVE-2026-40528

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu

3.8
CVE-2026-10299

A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown p

3.8
CVE-2026-45683

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0

3.8
CVE-2025-12656

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de

3.8
CVE-2026-53809

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr

3.8
CVE-2026-56212

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur

3.8
CVE-2026-8074

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act

3.8
CVE-2026-8823

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests whi

3.8
CVE-2026-0934

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.

3.8
CVE-2026-13322

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re

3.8
CVE-2026-42546

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte

3.8
CVE-2026-53763

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte

3.8
CVE-2026-42148

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

3.8
CVE-2026-59269

A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in

3.8
CVE-2026-15326

A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the f

3.8
CVE-2026-56281

Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit p

3.8
CVE-2026-9820

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end

3.8
CVE-2026-64614

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o

3.8
CVE-2026-64617

Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65061

Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65062

Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EX

3.8
CVE-2026-65063

Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EX

3.8
CVE-2026-65064

Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65066

Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_E

3.8
CVE-2026-65067

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65068

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_

3.8
CVE-2026-60405

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op

3.8
CVE-2026-61036

Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported ver

3.8
CVE-2026-12690

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions,

3.8
CVE-2026-14189

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them

3.8
CVE-2026-14221

The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-mana

3.8
CVE-2026-14222

The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its conne

3.8
CVE-2026-14197

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket

3.8
CVE-2026-67334

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp

3.8
CVE-2026-12730

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug

3.8
CVE-2025-14779

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet

3.8
CVE-2026-17011

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo

3.8
CVE-2026-14211

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started
Browse by year 2026