Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 336/436
5.3
CVE-2026-81724

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau

5.3
CVE-2026-37067

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauth

5.3
CVE-2026-59315

The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config

5.3
CVE-2026-54084

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

5.3
CVE-2026-38819

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaus

5.3
CVE-2026-12514

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capab

5.3
CVE-2026-14567

The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowi

5.3
CVE-2026-77701

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns t

5.3
CVE-2026-79706

The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to buil

5.3
CVE-2026-81777

Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.

5.3
CVE-2026-82248

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_s

5.3
CVE-2026-82256

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the N

5.3
CVE-2026-15603

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes l

5.3
CVE-2026-5096

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including

5.3
CVE-2026-82220

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

5.3
CVE-2026-82276

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec

5.3
CVE-2026-82290

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac

5.3
CVE-2026-19430

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and th

5.3
CVE-2026-82449

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrep

5.3
CVE-2026-82465

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.val

5.3
CVE-2026-82476

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata f

5.3
CVE-2026-82417

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a t

5.3
CVE-2026-82637

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta

5.3
CVE-2026-82548

A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the compo

5.3
CVE-2026-82652

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-vi

5.3
CVE-2026-82550

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component N

5.3
CVE-2026-82551

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_han

5.3
CVE-2026-82591

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the

5.3
CVE-2026-82602

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as

5.2
CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative

5.2
CVE-2025-5781

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac

5.2
CVE-2026-22191

Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary Angula

5.2
CVE-2026-32707

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it

5.2
CVE-2026-3503

Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi

5.2
CVE-2026-33014

EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat

5.2
CVE-2026-33015

EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop

5.2
CVE-2026-24153

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful ex

5.2
CVE-2026-32591

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u

5.2
CVE-2026-40335

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt

5.2
CVE-2026-40338

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the

5.2
CVE-2026-40339

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt

5.2
CVE-2026-35244

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme

5.2
CVE-2026-41469

Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaSc

5.2
CVE-2026-42077

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit

5.2
CVE-2026-40001

There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which

5.2
CVE-2026-41662

Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth

5.2
CVE-2025-68709

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe

5.2
CVE-2026-41984

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser

5.2
CVE-2026-49859

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des

5.2
CVE-2026-49860

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started