Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 335/454
7.5
CVE-2026-45820

fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with

7.5
CVE-2026-63047

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 -

7.5
CVE-2026-57600

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t

7.5
CVE-2026-65598

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a

7.5
CVE-2026-13182

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt f

7.5
CVE-2026-13183

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic

7.5
CVE-2026-13184

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKe

7.5
CVE-2026-13189

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell c

7.5
CVE-2026-32665

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b

7.5
CVE-2026-40691

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r

7.5
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with

7.5
CVE-2026-55973

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel

7.5
CVE-2026-62145

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe

7.5
CVE-2026-11331

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou

7.5
CVE-2026-11605

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco

7.5
CVE-2026-11622

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa

7.5
CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the z

7.5
CVE-2026-12617

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME

7.5
CVE-2026-13204

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for on

7.5
CVE-2026-64834

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp

7.5
CVE-2026-14899

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) ha

7.5
CVE-2026-13089

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorith

7.5
CVE-2026-63683

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP

7.5
CVE-2026-64792

Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extension

7.5
CVE-2026-64797

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client

7.5
CVE-2026-60370

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

7.5
CVE-2026-15074

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the

7.5
CVE-2026-12082

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes

7.5
CVE-2026-14291

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its

7.5
CVE-2026-9713

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'

7.5
CVE-2024-58330

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret

7.5
CVE-2026-52688

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

7.5
CVE-2026-64799

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions

7.5
CVE-2026-65430

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in

7.5
CVE-2026-65754

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c

7.5
CVE-2026-65755

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio

7.5
CVE-2026-64611

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing

7.5
CVE-2026-59547

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

7.5
CVE-2026-59554

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

7.5
CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

7.5
CVE-2026-61954

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

7.5
CVE-2026-65477

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

7.5
CVE-2026-65481

Contributor Local File Inclusion in Vino <= 1.9 versions.

7.5
CVE-2026-65493

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

7.5
CVE-2026-65495

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

7.5
CVE-2026-65500

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver

7.5
CVE-2026-14257

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the

7.5
CVE-2026-43823

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c

7.5
CVE-2026-15614

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid

7.5
CVE-2026-15615

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started