Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 335/436
5.3
CVE-2026-55419

Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/

5.3
CVE-2026-55619

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well

5.3
CVE-2026-77585

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result

5.3
CVE-2026-77680

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 f

5.3
CVE-2026-78991

Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

5.3
CVE-2026-79001

Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro

5.3
CVE-2026-79028

Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.3
CVE-2026-79030

Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.3
CVE-2026-79044

Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

5.3
CVE-2026-79074

Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

5.3
CVE-2026-79089

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

5.3
CVE-2026-79104

Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

5.3
CVE-2026-79147

Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende

5.3
CVE-2026-79181

Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

5.3
CVE-2026-79196

Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerin

5.3
CVE-2026-79220

Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

5.3
CVE-2026-79242

Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

5.3
CVE-2026-79265

Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

5.3
CVE-2026-79287

Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive in

5.3
CVE-2026-73335

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m

5.3
CVE-2026-13172

The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in

5.3
CVE-2026-13404

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (rel

5.3
CVE-2026-13406

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before r

5.3
CVE-2026-14550

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through i

5.3
CVE-2026-16986

The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored s

5.3
CVE-2026-19094

The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restr

5.3
CVE-2026-75798

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only f

5.3
CVE-2026-77694

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed t

5.3
CVE-2026-77754

The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJA

5.3
CVE-2026-77758

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal s

5.3
CVE-2026-80234

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remot

5.3
CVE-2026-3235

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc

5.3
CVE-2026-81033

Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller

5.3
CVE-2026-47844

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for

5.3
CVE-2026-67275

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi

5.3
CVE-2026-77507

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

5.3
CVE-2026-47845

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is

5.3
CVE-2026-47874

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor N

5.3
CVE-2026-81485

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the

5.3
CVE-2026-81486

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_conte

5.3
CVE-2026-16567

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token

5.3
CVE-2026-59271

When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown

5.3
CVE-2026-78125

The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in a

5.3
CVE-2026-81274

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

5.3
CVE-2026-81276

Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

5.3
CVE-2026-81560

A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of t

5.3
CVE-2026-81562

A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the fi

5.3
CVE-2026-11754

Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: thr

5.3
CVE-2026-80207

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso

5.3
CVE-2026-81664

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started