Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 347/454
7.5
CVE-2026-73246

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest

7.5
CVE-2026-73249

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar

7.5
CVE-2026-14925

The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo

7.5
CVE-2026-16253

The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto

7.5
CVE-2026-18048

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f

7.5
CVE-2026-18049

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its

7.5
CVE-2026-18789

The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality,

7.5
CVE-2025-41770

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem

7.5
CVE-2026-19566

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix

7.5
CVE-2025-59325

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline

7.5
CVE-2025-59327

In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, i

7.5
CVE-2025-59322

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v

7.5
CVE-2026-68757

A user with access to a valid SAML response may impersonate another user under specific conditions.

7.5
CVE-2026-73285

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a

7.5
CVE-2026-68968

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa

7.5
CVE-2026-48553

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom

7.5
CVE-2026-48554

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfilt

7.5
CVE-2026-16931

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero

7.5
CVE-2026-17271

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of in

7.5
CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is di

7.5
CVE-2026-72801

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthen

7.5
CVE-2026-73406

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_EN

7.5
CVE-2026-19654

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input se

7.5
CVE-2026-65370

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. Th

7.5
CVE-2026-73418

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the

7.5
CVE-2026-71469

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random b

7.5
CVE-2026-73493

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42,

7.5
CVE-2026-47717

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/pro

7.5
CVE-2026-0301

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u

7.5
CVE-2026-13610

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registrat

7.5
CVE-2026-19481

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart f

7.5
CVE-2026-19484

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can

7.5
CVE-2026-73622

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl

7.5
CVE-2026-73623

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta

7.5
CVE-2026-73626

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.i

7.5
CVE-2026-27345

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.

7.5
CVE-2026-27538

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

7.5
CVE-2026-28157

Subscriber Path Traversal in Do Lasso <= 358 versions.

7.5
CVE-2026-48702

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Un

7.5
CVE-2026-61980

Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.

7.5
CVE-2026-61984

Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

7.5
CVE-2026-66431

Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions

7.5
CVE-2026-66432

Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.

7.5
CVE-2026-66441

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.

7.5
CVE-2026-66443

Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.

7.5
CVE-2026-66461

Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.

7.5
CVE-2026-66462

Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.

7.5
CVE-2026-66463

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

7.5
CVE-2026-66466

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checko

7.5
CVE-2026-66469

Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started