Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 219/1152
8.6
CVE-2026-61045

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

8.6
CVE-2026-61228

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

8.6
CVE-2026-61230

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

8.6
CVE-2026-61286

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana

8.6
CVE-2026-62535

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

8.6
CVE-2026-62586

Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versi

8.6
CVE-2026-62599

Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integratio

8.6
CVE-2026-62620

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-62625

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-62628

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-62636

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-70721

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment

8.6
CVE-2026-70996

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.6
CVE-2026-71131

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

8.6
CVE-2026-73939

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.6
CVE-2026-52854

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to vers

8.6
CVE-2026-12983

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowi

8.6
CVE-2026-16616

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachabl

8.6
CVE-2026-16950

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it i

8.6
CVE-2026-75916

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup.

8.6
CVE-2026-75917

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (a

8.6
CVE-2026-66800

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a

8.6
CVE-2026-69519

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ

8.6
CVE-2026-69558

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose

8.6
CVE-2026-72848

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_d

8.6
CVE-2026-77775

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve

8.6
CVE-2026-75932

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authent

8.6
CVE-2026-34741

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated rem

8.6
CVE-2026-28171

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

8.6
CVE-2026-32477

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

8.6
CVE-2026-78284

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

8.6
CVE-2026-63587

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Aut

8.6
CVE-2026-55534

PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key bu

8.6
CVE-2022-50999

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions

8.6
CVE-2026-55539

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs

8.6
CVE-2026-54511

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStruc

8.6
CVE-2026-27330

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

8.6
CVE-2026-81573

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce

8.6
CVE-2026-81091

The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in librar

8.6
CVE-2026-81093

The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/co

8.6
CVE-2026-80590

In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before

8.6
CVE-2026-82286

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthent

8.6
CVE-2026-55848

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.

8.6
CVE-2026-16061

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its

8.6
CVE-2026-82641

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication,

8.6
CVE-2026-82645

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/get

8.5
CVE-2025-69414

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit

8.5
CVE-2025-31044

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE

8.5
CVE-2025-69351

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni

8.5
CVE-2025-22713

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommer

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started