Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 278/436
5.4
CVE-2026-14292

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t

5.4
CVE-2026-15234

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin

5.4
CVE-2026-15262

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out

5.4
CVE-2026-10773

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c

5.4
CVE-2026-67306

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu

5.4
CVE-2026-67310

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t

5.4
CVE-2026-14864

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s

5.4
CVE-2026-15385

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m

5.4
CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont

5.4
CVE-2026-16064

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o

5.4
CVE-2026-16292

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta

5.4
CVE-2026-18570

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen

5.4
CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th

5.4
CVE-2026-18584

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact

5.4
CVE-2026-28147

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa

5.4
CVE-2026-18651

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr

5.4
CVE-2026-18644

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /

5.4
CVE-2026-18645

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys

5.4
CVE-2026-49131

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir

5.4
CVE-2026-49132

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec

5.4
CVE-2026-52520

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/

5.4
CVE-2026-66316

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

5.4
CVE-2026-66317

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n

5.4
CVE-2026-14848

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified th

5.4
CVE-2026-14192

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and

5.4
CVE-2026-14219

URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM

5.4
CVE-2026-70367

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr

5.4
CVE-2026-67196

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in

5.4
CVE-2026-70481

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand

5.4
CVE-2026-16942

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand

5.4
CVE-2026-71275

OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r

5.4
CVE-2026-16071

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc

5.4
CVE-2026-70440

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a

5.4
CVE-2026-70441

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag

5.4
CVE-2026-70610

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,

5.4
CVE-2026-70612

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,

5.4
CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg

5.4
CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.

5.4
CVE-2026-18959

A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des

5.4
CVE-2026-13703

The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated

5.4
CVE-2026-16537

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin

5.4
CVE-2026-18395

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o

5.4
CVE-2025-13394

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque

5.4
CVE-2026-8166

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu

5.4
CVE-2026-18487

A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s

5.4
CVE-2026-54717

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable

5.4
CVE-2026-15245

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con

5.4
CVE-2026-15386

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att

5.4
CVE-2026-16027

Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ

5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started