Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 260/454
7.6
CVE-2026-61296

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Linear Asset Mana

7.6
CVE-2026-70678

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

7.6
CVE-2026-70725

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operation

7.6
CVE-2026-70764

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support

7.6
CVE-2026-70786

Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engin

7.6
CVE-2026-70791

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)

7.6
CVE-2026-70803

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support

7.6
CVE-2026-70864

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita

7.6
CVE-2026-70960

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.6
CVE-2026-71020

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.6
CVE-2026-71021

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.6
CVE-2026-71022

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.6
CVE-2026-71027

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.6
CVE-2026-71048

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

7.6
CVE-2026-53958

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to

7.6
CVE-2024-13942

Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me

7.6
CVE-2026-16828

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9

7.6
CVE-2026-68900

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js re

7.6
CVE-2026-76357

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the

7.6
CVE-2026-66677

Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

7.6
CVE-2026-74011

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP

7.6
CVE-2026-78270

Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.

7.6
CVE-2026-79667

Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several p

7.6
CVE-2026-69104

An authenticated user may initiate repository migration operations without required repository permissions, potentially

7.6
CVE-2026-55532

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin

7.6
CVE-2026-80186

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bl

7.6
CVE-2026-29988

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device mo

7.6
CVE-2026-79938

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privil

7.6
CVE-2026-77368

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler

7.6
CVE-2026-47666

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t

7.6
CVE-2026-66155

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions

7.6
CVE-2026-59284

There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commo

7.6
CVE-2026-38822

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client s

7.6
CVE-2026-82243

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint tha

7.6
CVE-2026-82017

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that

7.5
CVE-2025-68272

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in

7.5
CVE-2026-21428

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_h

7.5
CVE-2025-55065

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

7.5
CVE-2025-59384

A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil

7.5
CVE-2025-67269

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to com

7.5
CVE-2025-9110

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect

7.5
CVE-2025-67158

An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attacker

7.5
CVE-2025-67159

Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.

7.5
CVE-2025-67160

An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers

7.5
CVE-2026-21452

MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior

7.5
CVE-2025-68033

Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allo

7.5
CVE-2025-68547

Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Confi

7.5
CVE-2025-68850

Missing Authorization vulnerability in codepeople Sell Downloads sell-downloads allows Exploiting Incorrectly Configured

7.5
CVE-2025-67303

An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a

7.5
CVE-2024-30516

Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started