Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 344/454
7.5
CVE-2026-28140

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

7.5
CVE-2026-34501

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por

7.5
CVE-2026-34502

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache

7.5
CVE-2026-65504

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

7.5
CVE-2026-65523

Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0

7.5
CVE-2026-65543

Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.

7.5
CVE-2026-66712

Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

7.5
CVE-2026-70646

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` d

7.5
CVE-2026-18427

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file hand

7.5
CVE-2026-53977

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to termi

7.5
CVE-2026-53985

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's serv

7.5
CVE-2026-68749

Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthe

7.5
CVE-2026-68750

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenti

7.5
CVE-2026-10524

The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price

7.5
CVE-2026-10599

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact

7.5
CVE-2026-12584

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of inco

7.5
CVE-2026-13399

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a

7.5
CVE-2026-16619

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem

7.5
CVE-2026-16620

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist f

7.5
CVE-2026-19142

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engag

7.5
CVE-2026-19156

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal

7.5
CVE-2026-19158

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a us

7.5
CVE-2026-19159

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engag

7.5
CVE-2026-19165

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal

7.5
CVE-2026-19176

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render

7.5
CVE-2026-45378

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

7.5
CVE-2026-5855

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt

7.5
CVE-2026-67422

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0,

7.5
CVE-2026-70559

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t

7.5
CVE-2026-70636

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th

7.5
CVE-2026-71488

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf

7.5
CVE-2026-62918

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing

7.5
CVE-2026-14943

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d

7.5
CVE-2026-16041

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p

7.5
CVE-2026-16262

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating

7.5
CVE-2026-49007

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th

7.5
CVE-2026-71559

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de

7.5
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs

7.5
CVE-2026-20337

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi

7.5
CVE-2026-20338

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi

7.5
CVE-2026-20339

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do

7.5
CVE-2026-20345

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-20346

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-20347

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do

7.5
CVE-2026-20348

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-19082

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count

7.5
CVE-2025-63235

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON

7.5
CVE-2026-15972

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi

7.5
CVE-2026-62295

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11

7.5
CVE-2026-62296

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started