Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 330/436
5.3
CVE-2026-17021

The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif

5.3
CVE-2026-19074

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i

5.3
CVE-2026-66409

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma

5.3
CVE-2026-66411

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut

5.3
CVE-2026-72588

A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d

5.3
CVE-2026-72721

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec

5.3
CVE-2026-72723

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano

5.3
CVE-2026-68870

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va

5.3
CVE-2026-40130

SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta

5.3
CVE-2026-58247

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul

5.3
CVE-2026-66778

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A

5.3
CVE-2026-8158

The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to

5.3
CVE-2026-71218

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,

5.3
CVE-2026-72549

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers

5.3
CVE-2026-14180

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han

5.3
CVE-2026-62757

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit

5.3
CVE-2026-65777

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature ov

5.3
CVE-2026-20901

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta

5.3
CVE-2026-73228

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing

5.3
CVE-2026-71468

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly

5.3
CVE-2026-73244

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li

5.3
CVE-2026-66340

The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout

5.3
CVE-2025-15684

A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com

5.3
CVE-2026-16737

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca

5.3
CVE-2026-18035

The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo

5.3
CVE-2026-19073

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o

5.3
CVE-2026-15213

The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-

5.3
CVE-2026-16621

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee

5.3
CVE-2026-16990

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si

5.3
CVE-2026-17008

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i

5.3
CVE-2026-70466

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.

5.3
CVE-2026-71408

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.

5.3
CVE-2026-66377

An unauthenticated user may access restricted repository information under specific conditions.

5.3
CVE-2026-66381

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co

5.3
CVE-2026-68753

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in

5.3
CVE-2026-68760

An unauthenticated user may bypass authentication under specific cache conditions.

5.3
CVE-2026-73290

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req

5.3
CVE-2026-66384 KEV

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

5.3
CVE-2026-7427

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 1

5.3
CVE-2026-19643

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow

5.3
CVE-2026-72802

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that retu

5.3
CVE-2026-73306

Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the fa

5.3
CVE-2026-11932

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

5.3
CVE-2026-73429

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session wi

5.3
CVE-2026-73430

Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of servic

5.3
CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_functi

5.3
CVE-2026-13328

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-statu

5.3
CVE-2026-3835

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protect

5.3
CVE-2026-59502

: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

5.3
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started