Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 253/454
7.7
CVE-2026-68255

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response

7.7
CVE-2026-68340

In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks T

7.7
CVE-2026-18941

A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is

7.7
CVE-2026-18127

External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica

7.7
CVE-2026-48385

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

7.7
CVE-2026-48414

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged

7.7
CVE-2026-48447

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution

7.7
CVE-2026-66878

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable

7.7
CVE-2026-73122

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln

7.7
CVE-2026-16627

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditi

7.7
CVE-2026-16863

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o

7.7
CVE-2026-14866

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to

7.7
CVE-2026-73498

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, co

7.7
CVE-2026-65582

Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.

7.7
CVE-2026-66661

Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.

7.7
CVE-2026-58314

Two SSRF findings in Gitea 1.26.2

7.7
CVE-2026-72670

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a confi

7.7
CVE-2026-72672

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queri

7.7
CVE-2026-73530

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to rea

7.7
CVE-2026-72849

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows

7.7
CVE-2026-72857

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated user

7.7
CVE-2026-72859

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that all

7.7
CVE-2026-69101

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to

7.7
CVE-2026-72487

In the Linux kernel, the following vulnerability has been resolved: PCI: Check ROM header and data structure addr befor

7.7
CVE-2026-74869

stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows auth

7.7
CVE-2026-71567

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected with

7.7
CVE-2026-74234

Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaSc

7.7
CVE-2026-75842

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that

7.7
CVE-2026-50575

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi

7.7
CVE-2026-71365

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing

7.7
CVE-2026-71303

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when a

7.7
CVE-2026-71307

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only

7.7
CVE-2026-60733

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi

7.7
CVE-2026-60969

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

7.7
CVE-2026-60983

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.7
CVE-2026-61199

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The suppo

7.7
CVE-2026-61331

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).

7.7
CVE-2026-62467

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events).

7.7
CVE-2026-62571

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

7.7
CVE-2026-62593

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi

7.7
CVE-2026-62594

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi

7.7
CVE-2026-70687

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that

7.7
CVE-2026-70692

Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operat

7.7
CVE-2026-70694

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi

7.7
CVE-2026-70695

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi

7.7
CVE-2026-70717

Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are a

7.7
CVE-2026-70723

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment

7.7
CVE-2026-70771

Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). S

7.7
CVE-2026-70804

Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Test

7.7
CVE-2026-70827

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operat

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started