Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 346/454
7.5
CVE-2026-18611

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive

7.5
CVE-2026-18618

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn

7.5
CVE-2026-72914

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be

7.5
CVE-2026-72915

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta

7.5
CVE-2026-19424

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem

7.5
CVE-2026-15561

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at

7.5
CVE-2026-15562

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and

7.5
CVE-2026-15565

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on

7.5
CVE-2026-15567

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec

7.5
CVE-2026-71217

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON wit

7.5
CVE-2026-72543

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote

7.5
CVE-2026-72544

An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers

7.5
CVE-2026-72545

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote

7.5
CVE-2026-72548

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers

7.5
CVE-2026-72552

A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the

7.5
CVE-2026-72600

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download

7.5
CVE-2026-72601

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissi

7.5
CVE-2026-72602

A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attacke

7.5
CVE-2026-72605

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary

7.5
CVE-2026-72606

A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the

7.5
CVE-2026-69109

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v

7.5
CVE-2026-72766

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai

7.5
CVE-2026-18125

An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at

7.5
CVE-2026-48386

ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure

7.5
CVE-2026-48438

CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application deni

7.5
CVE-2026-48439

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

7.5
CVE-2026-54113

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o

7.5
CVE-2026-59132

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

7.5
CVE-2026-59134

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-61352

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all

7.5
CVE-2026-61363

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-62787

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

7.5
CVE-2026-62898

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

7.5
CVE-2026-62901

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

7.5
CVE-2026-65681

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

7.5
CVE-2026-73088

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to

7.5
CVE-2026-73089

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to

7.5
CVE-2016-20097

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthe

7.5
CVE-2022-50997

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint th

7.5
CVE-2026-48416

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

7.5
CVE-2026-72713

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-cre

7.5
CVE-2026-18697

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce

7.5
CVE-2026-48802

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta

7.5
CVE-2026-48809

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw

7.5
CVE-2026-13457

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all

7.5
CVE-2026-48804

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store

7.5
CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent

7.5
CVE-2026-73232

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory

7.5
CVE-2026-19558

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal

7.5
CVE-2026-29036

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started