Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 327/436
5.3
CVE-2026-28145

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User

5.3
CVE-2026-54909

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed

5.3
CVE-2026-12966

The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted

5.3
CVE-2026-13604

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit

5.3
CVE-2026-14822

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i

5.3
CVE-2026-14840

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien

5.3
CVE-2026-15932

The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download

5.3
CVE-2025-14073

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur

5.3
CVE-2026-11995

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress

5.3
CVE-2026-15018

The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor

5.3
CVE-2026-18059

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp

5.3
CVE-2026-67335

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-

5.3
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR

5.3
CVE-2026-67353

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit

5.3
CVE-2026-59640

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue

5.3
CVE-2026-59641

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss

5.3
CVE-2026-59647

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects

5.3
CVE-2026-59648

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff

5.3
CVE-2026-18582

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Re

5.3
CVE-2026-12860

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu

5.3
CVE-2026-18583

A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc

5.3
CVE-2026-12259

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to

5.3
CVE-2026-60011

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image

5.3
CVE-2026-62416

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir

5.3
CVE-2026-18604

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D

5.3
CVE-2026-18610

A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp

5.3
CVE-2026-69153

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract

5.3
CVE-2026-18646

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system

5.3
CVE-2026-18648

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat

5.3
CVE-2026-58041

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont

5.3
CVE-2026-18720

A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?

5.3
CVE-2026-16536

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef

5.3
CVE-2026-14202

Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human

5.3
CVE-2026-15337

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()

5.3
CVE-2026-15830

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome

5.3
CVE-2026-18784

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute

5.3
CVE-2026-18785

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli

5.3
CVE-2026-47622

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con

5.3
CVE-2026-70487

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di

5.3
CVE-2026-18853

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu

5.3
CVE-2026-45705

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin

5.3
CVE-2026-16981

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa

5.3
CVE-2026-55998

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid

5.3
CVE-2026-71203

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke

5.3
CVE-2026-71210

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r

5.3
CVE-2026-12762

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti

5.3
CVE-2026-18531

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use

5.3
CVE-2026-70607

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,

5.3
CVE-2026-18974

A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the

5.3
CVE-2026-14240

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started