Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 343/436
5.0
CVE-2025-12317

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue

5.0
CVE-2026-62293

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11

5.0
CVE-2026-16955

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi

5.0
CVE-2026-19353

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the fi

5.0
CVE-2026-19075

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any

5.0
CVE-2026-61368

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.

5.0
CVE-2026-71475

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data

5.0
CVE-2026-73480

gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers

5.0
CVE-2026-73479

dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attac

5.0
CVE-2026-12519

The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendo

5.0
CVE-2026-65339

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.

5.0
CVE-2026-62460

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

5.0
CVE-2026-20314

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (

5.0
CVE-2026-76375

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could

5.0
CVE-2026-77066

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to ax

5.0
CVE-2026-77067

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any addres

5.0
CVE-2025-62306

HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a

5.0
CVE-2026-76993

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the compone

5.0
CVE-2026-55067

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v

5.0
CVE-2026-55425

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity

5.0
CVE-2026-82486

A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the compone

5.0
CVE-2026-82594

A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the co

4.9
CVE-2025-66023

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre

4.9
CVE-2025-52426

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52430

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52431

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53405

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53414

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53589

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53590

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53596

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-54164

An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta

4.9
CVE-2025-54165

An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta

4.9
CVE-2025-54166

An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta

4.9
CVE-2025-57705

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating

4.9
CVE-2025-59380

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

4.9
CVE-2025-59381

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

4.9
CVE-2025-14830

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artif

4.9
CVE-2025-13409

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet

4.9
CVE-2025-14719

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and es

4.9
CVE-2025-49335

Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg

4.9
CVE-2025-62327

In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti

4.9
CVE-2026-20029

A vulnerability in the licensing features of&nbsp;Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co

4.9
CVE-2026-22242

CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in

4.9
CVE-2026-0678

The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c

4.9
CVE-2025-67081

An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro

4.9
CVE-2025-12984

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in

4.9
CVE-2026-1223

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability,

4.9
CVE-2025-13925

IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged

4.9
CVE-2026-21936

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started