Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 326/436
5.3
CVE-2026-15411

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for

5.3
CVE-2026-16773

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In

5.3
CVE-2026-16774

The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the

5.3
CVE-2026-62434

A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. Thi

5.3
CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To

5.3
CVE-2026-50738

A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aft

5.3
CVE-2026-16581

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulner

5.3
CVE-2026-49447

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as

5.3
CVE-2026-56722

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can byp

5.3
CVE-2026-59943

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted con

5.3
CVE-2026-66064

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler

5.3
CVE-2026-11351

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API e

5.3
CVE-2026-13692

The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying

5.3
CVE-2026-4604

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

5.3
CVE-2026-18174

@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header

5.3
CVE-2026-66488

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

5.3
CVE-2026-66489

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

5.3
CVE-2026-67217

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl

5.3
CVE-2026-67193

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to

5.3
CVE-2026-20316 KEV

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti

5.3
CVE-2026-59900

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,

5.3
CVE-2026-5489

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo

5.3
CVE-2026-67430

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran

5.3
CVE-2026-6336

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 1

5.3
CVE-2026-64685

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.

5.3
CVE-2026-17909

Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote

5.3
CVE-2026-17914

Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain pot

5.3
CVE-2026-17978

Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtai

5.3
CVE-2026-1982

The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, an

5.3
CVE-2026-13143

The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal po

5.3
CVE-2026-13345

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility

5.3
CVE-2026-14305

The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all

5.3
CVE-2026-15250

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated

5.3
CVE-2026-15255

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in

5.3
CVE-2026-15257

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr

5.3
CVE-2026-16531

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a

5.3
CVE-2026-64635

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an

5.3
CVE-2026-44102

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f

5.3
CVE-2026-44103

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore

5.3
CVE-2026-58218

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY

5.3
CVE-2026-58216

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi

5.3
CVE-2026-11904

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident

5.3
CVE-2026-43833

Full details and mitigation steps are currently restricted and will be published at a later date.

5.3
CVE-2026-14317

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t

5.3
CVE-2026-14843

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target

5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi

5.3
CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the

5.3
CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access

5.3
CVE-2026-17567

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

5.3
CVE-2026-64607

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started