Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 251/436
5.5
CVE-2026-79769

Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#in

5.5
CVE-2026-13478

The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by p

5.5
CVE-2026-48429

Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denia

5.5
CVE-2026-59983

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-59984

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-71441

Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An att

5.5
CVE-2026-75752

Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memo

5.5
CVE-2026-76198

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst

5.5
CVE-2026-59985

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-61555

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

5.5
CVE-2026-64705

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma

5.5
CVE-2026-65367

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18

5.5
CVE-2026-68514

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

5.5
CVE-2026-65088

NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive inf

5.5
CVE-2026-78957

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitiv

5.5
CVE-2026-79146

Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain

5.5
CVE-2026-3035

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3

5.5
CVE-2026-79902

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin

5.5
CVE-2026-80158

A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter

5.5
CVE-2026-81687

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specifi

5.5
CVE-2026-81697

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution fla

5.5
CVE-2026-81703

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m

5.5
CVE-2026-34616

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex

5.5
CVE-2026-34620

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to applicat

5.5
CVE-2026-81833

A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function

5.5
CVE-2026-81835

A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instruct

5.5
CVE-2026-81847

A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeli

5.5
CVE-2026-82181

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote

5.5
CVE-2026-82327

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper t

5.5
CVE-2026-82640

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or

5.4
CVE-2026-21431

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `

5.4
CVE-2026-21432

Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can

5.4
CVE-2026-21483

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged use

5.4
CVE-2025-15449

A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the

5.4
CVE-2025-5591

Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to

5.4
CVE-2023-52212

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issu

5.4
CVE-2025-67316

An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage

5.4
CVE-2025-68954

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co

5.4
CVE-2025-13766

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz

5.4
CVE-2025-69341

Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad

5.4
CVE-2025-69349

Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Confi

5.4
CVE-2025-69352

Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C

5.4
CVE-2025-13744

An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server

5.4
CVE-2025-12449

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis

5.4
CVE-2025-14802

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and i

5.4
CVE-2025-15479

Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru

5.4
CVE-2025-61782

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.

5.4
CVE-2025-12776

The Report Builder component of the application stores user input directly in a web page and displays it to other users,

5.4
CVE-2026-21691

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

5.4
CVE-2026-21883

Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started