Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 315/454
7.5
CVE-2026-48872

Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.

7.5
CVE-2026-48873

Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.

7.5
CVE-2026-48883

Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.

7.5
CVE-2026-49056

Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <

7.5
CVE-2026-49061

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

7.5
CVE-2026-49066

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

7.5
CVE-2026-49068

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

7.5
CVE-2026-49070

Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

7.5
CVE-2026-49078

Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.

7.5
CVE-2026-49083

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

7.5
CVE-2026-49110

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

7.5
CVE-2026-49112

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

7.5
CVE-2026-52692

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

7.5
CVE-2026-52694

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

7.5
CVE-2026-52695

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

7.5
CVE-2026-52699

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

7.5
CVE-2025-68045

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

7.5
CVE-2026-39490

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

7.5
CVE-2026-52711

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

7.5
CVE-2026-8176

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca

7.5
CVE-2026-12305

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12310

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12312

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12314

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12317

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

7.5
CVE-2026-12398

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (

7.5
CVE-2026-0156

In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This

7.5
CVE-2026-35269

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers

7.5
CVE-2026-35275

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported

7.5
CVE-2026-35295

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

7.5
CVE-2026-46791

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

7.5
CVE-2026-46862

Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are aff

7.5
CVE-2026-46863

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supp

7.5
CVE-2026-46873

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v

7.5
CVE-2026-46934

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte

7.5
CVE-2026-46935

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte

7.5
CVE-2026-46955

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions

7.5
CVE-2026-46957

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo

7.5
CVE-2026-46958

Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S

7.5
CVE-2026-46959

Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S

7.5
CVE-2026-46966

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level

7.5
CVE-2026-46971

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.5
CVE-2026-46974

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.5
CVE-2024-32729

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversatio

7.5
CVE-2025-49403

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

7.5
CVE-2025-69103

Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.

7.5
CVE-2025-69131

Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 ve

7.5
CVE-2026-12199

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNe

7.5
CVE-2026-12360

The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list

7.5
CVE-2026-12445

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to instal

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started