Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 334/436
5.3
CVE-2026-13736

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on a

5.3
CVE-2026-16575

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict acc

5.3
CVE-2026-16962

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its p

5.3
CVE-2026-19441

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.

5.3
CVE-2026-59323

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of serv

5.3
CVE-2026-15150

The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification m

5.3
CVE-2026-16650

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events

5.3
CVE-2026-17559

The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which RE

5.3
CVE-2026-75928

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in req

5.3
CVE-2026-27463

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi

5.3
CVE-2026-69228

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot

5.3
CVE-2026-53497

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut

5.3
CVE-2026-75027

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8

5.3
CVE-2026-16612

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth

5.3
CVE-2026-16738

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway w

5.3
CVE-2026-3424

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e

5.3
CVE-2026-56380

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica

5.3
CVE-2026-63311

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid

5.3
CVE-2026-12999

The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a

5.3
CVE-2026-78051

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f

5.3
CVE-2026-75922

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco

5.3
CVE-2026-78148

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of t

5.3
CVE-2026-19853

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers

5.3
CVE-2026-8173

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an aut

5.3
CVE-2026-78258

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

5.3
CVE-2026-78278

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

5.3
CVE-2026-78291

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

5.3
CVE-2025-68833

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u

5.3
CVE-2026-21755

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or creden

5.3
CVE-2026-13343

The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (

5.3
CVE-2026-63621

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject

5.3
CVE-2026-75099

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through

5.3
CVE-2026-13213

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set uncondit

5.3
CVE-2026-77310

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prio

5.3
CVE-2026-78430

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall o

5.3
CVE-2026-16782

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A m

5.3
CVE-2026-56708

Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attac

5.3
CVE-2026-72699

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register(

5.3
CVE-2026-75575

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may

5.3
CVE-2026-10627

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass i

5.3
CVE-2026-17587

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass i

5.3
CVE-2026-78684

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod

5.3
CVE-2026-79660

Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON seri

5.3
CVE-2026-79668

Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una

5.3
CVE-2026-79771

Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strin

5.3
CVE-2026-79772

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning

5.3
CVE-2026-79776

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication ru

5.3
CVE-2026-79778

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a

5.3
CVE-2026-79779

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization an

5.3
CVE-2026-79780

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, al

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started