Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 314/454
7.5
CVE-2026-50108

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifyin

7.5
CVE-2026-44786

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be

7.5
CVE-2026-4870

IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of servi

7.5
CVE-2026-53834

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow

7.5
CVE-2026-53868

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary

7.5
CVE-2026-9848

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers

7.5
CVE-2016-20076

WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrar

7.5
CVE-2016-20081

WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attacke

7.5
CVE-2018-25437

WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta

7.5
CVE-2026-49064

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da

7.5
CVE-2026-5079

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi

7.5
CVE-2026-9863

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta

7.5
CVE-2026-47777

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in

7.5
CVE-2026-39007

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th

7.5
CVE-2026-41708

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service

7.5
CVE-2026-50870

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attacker

7.5
CVE-2026-50877

An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names cont

7.5
CVE-2026-50878

An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv

7.5
CVE-2026-50879

An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser

7.5
CVE-2026-50882

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)

7.5
CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to

7.5
CVE-2026-50889

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (

7.5
CVE-2025-59133

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

7.5
CVE-2026-25425

Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.

7.5
CVE-2026-27089

Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.

7.5
CVE-2026-34886

Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.

7.5
CVE-2026-34891

Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.

7.5
CVE-2026-34898

Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.

7.5
CVE-2026-39480

Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.

7.5
CVE-2026-39503

Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.

7.5
CVE-2026-39513

Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.

7.5
CVE-2026-39524

Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.

7.5
CVE-2026-39533

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.

7.5
CVE-2026-39534

Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

7.5
CVE-2026-40741

Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.

7.5
CVE-2026-40762

Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.

7.5
CVE-2026-40767

Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.

7.5
CVE-2026-40774

Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.

7.5
CVE-2026-40776

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

7.5
CVE-2026-40781

Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.

7.5
CVE-2026-40789

Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.

7.5
CVE-2026-42384

Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

7.5
CVE-2026-42666

Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.

7.5
CVE-2026-42667

Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.

7.5
CVE-2026-42668

Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.

7.5
CVE-2026-45441

Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.

7.5
CVE-2026-47261

Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is gi

7.5
CVE-2026-48708

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template en

7.5
CVE-2026-48835

Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.

7.5
CVE-2026-48868

Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started