Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 24/42
3.3
CVE-2026-56089

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l

3.3
CVE-2026-75483

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt

3.3
CVE-2026-63632

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0,

3.3
CVE-2026-75904

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates o

3.3
CVE-2026-62526

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security).

3.3
CVE-2026-62577

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

3.3
CVE-2026-70853

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

3.3
CVE-2026-70962

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

3.3
CVE-2026-71072

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

3.3
CVE-2026-71089

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

3.3
CVE-2026-76014

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/w

3.3
CVE-2026-49426

When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup f

3.3
CVE-2026-49431

The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is

3.3
CVE-2026-49423

When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index

3.3
CVE-2026-16891

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out

3.3
CVE-2026-76137

Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local

3.3
CVE-2026-78638

A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dis

3.3
CVE-2026-43657

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malic

3.3
CVE-2026-54548

kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH

3.3
CVE-2026-81685

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to

3.3
CVE-2026-81694

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the

3.3
CVE-2026-81695

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt

3.3
CVE-2026-81696

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info

3.3
CVE-2026-81715

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p

3.3
CVE-2026-38093

file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22

3.3
CVE-2026-82596

A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDe

3.2
CVE-2025-14058

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us

3.2
CVE-2026-25211

Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

3.2
CVE-2026-25815

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exp

3.2
CVE-2026-31369

PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab

3.2
CVE-2026-35249

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

3.2
CVE-2026-41988

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6.

3.2
CVE-2026-43969

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split

3.2
CVE-2026-45362

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

3.2
CVE-2026-44220

ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function i

3.2
CVE-2026-0238

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c

3.2
CVE-2026-46815

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v

3.2
CVE-2026-46816

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v

3.2
CVE-2026-46874

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

3.2
CVE-2026-46977

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v

3.2
CVE-2026-49356

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an a

3.2
CVE-2026-47043

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

3.2
CVE-2026-47055

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

3.2
CVE-2026-60160

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

3.2
CVE-2026-59292

PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdi

3.1
CVE-2025-15454

A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file sr

3.1
CVE-2025-15224

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s

3.1
CVE-2025-53470

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo

3.1
CVE-2025-14822

Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica

3.1
CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started