Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 342/454
7.5
CVE-2026-15314

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT

7.5
CVE-2026-56848

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m

7.5
CVE-2026-24255

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash

7.5
CVE-2026-47612

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper lim

7.5
CVE-2026-47613

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a rest

7.5
CVE-2026-47614

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful e

7.5
CVE-2026-47615

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a

7.5
CVE-2026-47616

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side

7.5
CVE-2026-47617

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side

7.5
CVE-2026-47618

NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause serv

7.5
CVE-2026-66901

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated

7.5
CVE-2026-45103

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP

7.5
CVE-2026-67855

open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA

7.5
CVE-2026-67856

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri

7.5
CVE-2026-67857

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u

7.5
CVE-2026-67858

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di

7.5
CVE-2026-67859

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover

7.5
CVE-2026-67860

open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database

7.5
CVE-2026-67861

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo

7.5
CVE-2026-67862

open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c

7.5
CVE-2026-18907

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc

7.5
CVE-2026-15918

VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t

7.5
CVE-2026-66257

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-66273

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential

7.5
CVE-2026-67465

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-67551

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d

7.5
CVE-2026-67588

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-67589

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential

7.5
CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential

7.5
CVE-2026-68074

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-15372

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported m

7.5
CVE-2026-16036

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login

7.5
CVE-2026-16055

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au

7.5
CVE-2026-16561

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action

7.5
CVE-2026-16573

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un

7.5
CVE-2026-16602

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u

7.5
CVE-2026-16603

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST

7.5
CVE-2026-16604

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before

7.5
CVE-2026-16736

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett

7.5
CVE-2026-66274

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-67552

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-67590

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-67592

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

7.5
CVE-2026-68073

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-12000

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and

7.5
CVE-2026-18881

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter

7.5
CVE-2026-59675

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz

7.5
CVE-2026-61483

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al

7.5
CVE-2026-61485

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af

7.5
CVE-2026-64577

In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started