Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 331/436
5.3
CVE-2026-73349

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

5.3
CVE-2026-73353

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

5.3
CVE-2026-73401

Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

5.3
CVE-2026-73403

Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

5.3
CVE-2026-53794

rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-al

5.3
CVE-2026-53798

rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that al

5.3
CVE-2026-70459

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot

5.3
CVE-2026-73508

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.

5.3
CVE-2026-73555

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in

5.3
CVE-2026-73556

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet

5.3
CVE-2026-73558

vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x *

5.3
CVE-2026-19487

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends

5.3
CVE-2026-58507

Private Repository Existence Disclosure via go-get Meta Endpoint

5.3
CVE-2026-73565

@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request t

5.3
CVE-2026-16859

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

5.3
CVE-2026-16861

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

5.3
CVE-2026-16929

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer

5.3
CVE-2026-17076

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DR

5.3
CVE-2026-17077

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitializ

5.3
CVE-2026-17078

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

5.3
CVE-2026-17212

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

5.3
CVE-2026-17216

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when pro

5.3
CVE-2026-17468

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use

5.3
CVE-2026-17649

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

5.3
CVE-2026-18020

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bo

5.3
CVE-2026-73840

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST

5.3
CVE-2026-19770

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadR

5.3
CVE-2026-19827

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin

5.3
CVE-2026-19830

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of th

5.3
CVE-2026-1621

Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of

5.3
CVE-2026-19879

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method p

5.3
CVE-2026-66272

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vul

5.3
CVE-2026-73845

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_m

5.3
CVE-2026-19636

An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effec

5.3
CVE-2026-50029

js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in

5.3
CVE-2026-16905

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due t

5.3
CVE-2026-74242

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Uni

5.3
CVE-2026-12128

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` par

5.3
CVE-2026-8840

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versi

5.3
CVE-2026-15993

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind S

5.3
CVE-2026-14229

The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor docu

5.3
CVE-2026-19903

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db

5.3
CVE-2026-15441

The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 vi

5.3
CVE-2026-12998

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D

5.3
CVE-2026-19978

A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted eleme

5.3
CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership che

5.3
CVE-2026-19987

A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknow

5.3
CVE-2026-53960

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwis

5.3
CVE-2026-68520

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py c

5.3
CVE-2026-19608

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained a

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started