Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 219/454
7.8
CVE-2026-57245

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida

7.8
CVE-2026-57246

When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature

7.8
CVE-2026-57247

The application re-enters the document structure via field processing and deletes the current page, and then continues u

7.8
CVE-2026-57248

When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object

7.8
CVE-2026-57249

After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e

7.8
CVE-2026-57250

When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi

7.8
CVE-2026-57251

The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper

7.8
CVE-2026-57252

When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio

7.8
CVE-2026-57254

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,

7.8
CVE-2026-57256

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi

7.8
CVE-2026-57260

The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re

7.8
CVE-2026-22927

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

7.8
CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina

7.8
CVE-2026-55878

Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install

7.8
CVE-2026-41857

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope

7.8
CVE-2026-47829

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s

7.8
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows

7.8
CVE-2026-0276

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to

7.8
CVE-2026-0278

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow

7.8
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p

7.8
CVE-2026-59858

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco

7.8
CVE-2026-61437

PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl

7.8
CVE-2026-34196

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a

7.8
CVE-2026-41154

Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls.

7.8
CVE-2026-45196

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r

7.8
CVE-2026-45203

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor

7.8
CVE-2026-7639

Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte

7.8
CVE-2026-10667

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l

7.8
CVE-2026-15506

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func

7.8
CVE-2026-7162

Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to

7.8
CVE-2026-9492

The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an

7.8
CVE-2026-10669

On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the

7.8
CVE-2026-42982

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p

7.8
CVE-2026-44800

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-49166

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49170

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi

7.8
CVE-2026-49173

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49175

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49783

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a secu

7.8
CVE-2026-49792

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

7.8
CVE-2026-49793

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally

7.8
CVE-2026-49796

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-49797

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-49800

Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elev

7.8
CVE-2026-49808

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an

7.8
CVE-2026-50293

Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50308

Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50311

Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started