Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 345/454
7.5
CVE-2026-65819

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con

7.5
CVE-2026-47249

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling

7.5
CVE-2026-52878

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a

7.5
CVE-2026-52879

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess

7.5
CVE-2026-52880

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable

7.5
CVE-2026-16578

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n

7.5
CVE-2026-16594

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti

7.5
CVE-2026-17510

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero leng

7.5
CVE-2026-10595

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen

7.5
CVE-2026-16988

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat

7.5
CVE-2026-18032

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent

7.5
CVE-2026-18357

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of

7.5
CVE-2026-18464

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a

7.5
CVE-2026-14206

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns

7.5
CVE-2026-17022

The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before

7.5
CVE-2026-17541

The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin

7.5
CVE-2026-17542

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto

7.5
CVE-2026-18470

The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a

7.5
CVE-2026-18946

The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr

7.5
CVE-2026-66403

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio

7.5
CVE-2026-44630

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus

7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version

7.5
CVE-2026-61899

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v

7.5
CVE-2026-65942

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v

7.5
CVE-2026-72571

A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker t

7.5
CVE-2026-72572

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and down

7.5
CVE-2026-72579

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept

7.5
CVE-2026-72582

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras

7.5
CVE-2026-72586

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que

7.5
CVE-2026-68096

In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe

7.5
CVE-2026-68119

In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding

7.5
CVE-2026-68120

In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang caused by hardware pa

7.5
CVE-2026-68129

In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the

7.5
CVE-2026-68131

In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object

7.5
CVE-2026-68141

In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_s

7.5
CVE-2026-68155

In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors

7.5
CVE-2026-68157

In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Loca

7.5
CVE-2026-68287

In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attr

7.5
CVE-2026-68299

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Ge

7.5
CVE-2026-68315

In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strrese

7.5
CVE-2026-68379

In the Linux kernel, the following vulnerability has been resolved: tcp: fix TIME_WAIT socket reference leak on PSP pol

7.5
CVE-2026-68414

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on u

7.5
CVE-2026-72688

A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at

7.5
CVE-2026-72689

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate

7.5
CVE-2026-72691

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at

7.5
CVE-2026-72692

A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att

7.5
CVE-2026-48048

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta

7.5
CVE-2026-71962

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants

7.5
CVE-2026-72871

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith

7.5
CVE-2026-11810

The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started