Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 339/454
7.5
CVE-2026-17916

Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co

7.5
CVE-2026-17930

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack

7.5
CVE-2026-17948

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic

7.5
CVE-2026-17952

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to i

7.5
CVE-2026-17979

Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox

7.5
CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ

7.5
CVE-2026-12500

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a

7.5
CVE-2026-12687

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th

7.5
CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied

7.5
CVE-2026-15240

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper

7.5
CVE-2026-16529

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU proce

7.5
CVE-2026-44107

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f

7.5
CVE-2026-54365

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe

7.5
CVE-2026-54366

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack

7.5
CVE-2026-57859

e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a

7.5
CVE-2026-60074

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran

7.5
CVE-2026-60075

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi

7.5
CVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen

7.5
CVE-2026-12947

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive infor

7.5
CVE-2026-14519

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r

7.5
CVE-2026-16308

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remo

7.5
CVE-2026-41186

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components

7.5
CVE-2026-67349

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm

7.5
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR

7.5
CVE-2026-10842

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T

7.5
CVE-2026-28811

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver

7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s

7.5
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the

7.5
CVE-2026-62663

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt

7.5
CVE-2026-9322

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a

7.5
CVE-2024-25039

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1

7.5
CVE-2026-10545

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect

7.5
CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

7.5
CVE-2026-12942

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c

7.5
CVE-2026-15977

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf

7.5
CVE-2026-15978

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end

7.5
CVE-2026-18140

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy

7.5
CVE-2026-61536

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J

7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.

7.5
CVE-2026-68500

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli

7.5
CVE-2026-18064

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s

7.5
CVE-2026-63559

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r

7.5
CVE-2026-66360

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis

7.5
CVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up

7.5
CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc

7.5
CVE-2026-43829

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-43831

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-43832

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-56671

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ

7.5
CVE-2026-56673

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started