Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 340/454
7.5
CVE-2026-63222

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us

7.5
CVE-2026-12720

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data

7.5
CVE-2026-14319

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri

7.5
CVE-2026-14333

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p

7.5
CVE-2026-14830

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually

7.5
CVE-2026-14930

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front

7.5
CVE-2026-15048

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowin

7.5
CVE-2026-65309

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form

7.5
CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu

7.5
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle

7.5
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function

7.5
CVE-2026-18358

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo

7.5
CVE-2026-18446

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer

7.5
CVE-2026-17347

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that

7.5
CVE-2026-52856

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a

7.5
CVE-2026-53503

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>,

7.5
CVE-2026-53504

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expressio

7.5
CVE-2026-53505

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) fi

7.5
CVE-2026-53599

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/s

7.5
CVE-2026-62999

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-direc

7.5
CVE-2026-15006

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln

7.5
CVE-2026-14839

The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public R

7.5
CVE-2026-18536

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:

7.5
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept

7.5
CVE-2026-67290

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG

7.5
CVE-2026-67291

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments

7.5
CVE-2026-67296

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid

7.5
CVE-2026-67297

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses

7.5
CVE-2026-67298

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_

7.5
CVE-2026-67299

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER

7.5
CVE-2026-67300

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI

7.5
CVE-2026-67301

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an

7.5
CVE-2026-67304

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when

7.5
CVE-2026-67322

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied rem

7.5
CVE-2026-54894

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

7.5
CVE-2026-55733

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

7.5
CVE-2026-55734

Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a

7.5
CVE-2026-55735

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi

7.5
CVE-2026-13339

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1

7.5
CVE-2026-18352

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,

7.5
CVE-2026-15151

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its

7.5
CVE-2026-15206

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w

7.5
CVE-2026-15236

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party

7.5
CVE-2026-15241

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o

7.5
CVE-2026-16261

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req

7.5
CVE-2026-16285

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str

7.5
CVE-2026-16540

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati

7.5
CVE-2026-67357

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that

7.5
CVE-2026-68578

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p

7.5
CVE-2026-68580

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started