Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 254/454
7.7
CVE-2026-70828

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.7
CVE-2026-70857

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are

7.7
CVE-2026-70894

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu

7.7
CVE-2026-70942

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.7
CVE-2026-70945

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

7.7
CVE-2026-70988

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.7
CVE-2026-71056

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).

7.7
CVE-2026-71141

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.7
CVE-2026-76225

ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation th

7.7
CVE-2026-16819

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise d

7.7
CVE-2026-53549

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

7.7
CVE-2026-54493

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation

7.7
CVE-2026-75569

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without

7.7
CVE-2026-76344

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

7.7
CVE-2026-73137

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A te

7.7
CVE-2026-17003

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integr

7.7
CVE-2026-17024

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper ce

7.7
CVE-2026-17423

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a

7.7
CVE-2026-69855

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information o

7.7
CVE-2026-73267

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissi

7.7
CVE-2026-55621

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for

7.7
CVE-2026-55622

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for

7.7
CVE-2026-54457

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e

7.7
CVE-2026-34948

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are pr

7.7
CVE-2026-71366

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Matterm

7.7
CVE-2026-56707

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects

7.7
CVE-2026-19851

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attack

7.7
CVE-2026-79659

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses un

7.7
CVE-2026-79245

Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer p

7.7
CVE-2026-57171

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions

7.7
CVE-2026-75797

The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesyste

7.7
CVE-2026-61792

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

7.7
CVE-2026-61617

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13

7.7
CVE-2026-47879

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto de

7.7
CVE-2026-77017

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine t

7.7
CVE-2026-81576

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on

7.7
CVE-2026-81679

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST AP

7.7
CVE-2026-75889

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor reso

7.7
CVE-2026-82242

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpo

7.7
CVE-2026-81490

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling

7.7
CVE-2026-41012

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vC

7.7
CVE-2026-16600

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does

7.6
CVE-2025-36589

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul

7.6
CVE-2026-22230

OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access fu

7.6
CVE-2025-69195

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo

7.6
CVE-2025-59057

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0

7.6
CVE-2025-71100

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9

7.6
CVE-2026-1008

A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient ser

7.6
CVE-2026-1007

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny

7.6
CVE-2025-27380

HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attac

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started