Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 259/454
7.6
CVE-2026-61325

Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The

7.6
CVE-2026-62515

Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Ope

7.6
CVE-2026-62518

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).

7.6
CVE-2026-65462

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

7.6
CVE-2026-65532

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

7.6
CVE-2026-59537

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versio

7.6
CVE-2026-66427

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

7.6
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification

7.6
CVE-2026-16969

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the

7.6
CVE-2026-18360

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the

7.6
CVE-2026-18361

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the

7.6
CVE-2026-18378

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t

7.6
CVE-2026-18381

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r

7.6
CVE-2026-41703

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr

7.6
CVE-2026-67527

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc

7.6
CVE-2026-10685

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked

7.6
CVE-2026-67352

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows

7.6
CVE-2026-25292

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration

7.6
CVE-2026-71294

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated.

7.6
CVE-2026-34966

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass

7.6
CVE-2026-67621

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf

7.6
CVE-2026-19387

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D

7.6
CVE-2026-72594

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic

7.6
CVE-2026-18621

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde

7.6
CVE-2026-44763

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation

7.6
CVE-2026-48766

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr

7.6
CVE-2026-48415

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

7.6
CVE-2026-48767

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain

7.6
CVE-2026-18693

An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges

7.6
CVE-2026-73264

Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce

7.6
CVE-2026-16907

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bound

7.6
CVE-2026-17111

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statement

7.6
CVE-2026-73326

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access a

7.6
CVE-2026-73346

Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.

7.6
CVE-2026-73509

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename hand

7.6
CVE-2026-16961

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, wh

7.6
CVE-2026-72669

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the

7.6
CVE-2026-72853

Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup

7.6
CVE-2026-73408

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multip

7.6
CVE-2026-72825

The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/

7.6
CVE-2026-65822

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/repo

7.6
CVE-2026-75831

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through t

7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH

7.6
CVE-2026-49227

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

7.6
CVE-2026-49222

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

7.6
CVE-2026-49223

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

7.6
CVE-2026-60748

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support

7.6
CVE-2026-60909

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.6
CVE-2026-61208

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

7.6
CVE-2026-61227

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started