Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 349/436
4.9
CVE-2026-15445

The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio

4.9
CVE-2026-15458

The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio

4.9
CVE-2026-15651

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para

4.9
CVE-2026-15727

The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in

4.9
CVE-2026-14782

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu

4.9
CVE-2026-15457

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa

4.9
CVE-2026-16072

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to mana

4.9
CVE-2026-16106

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when

4.9
CVE-2026-48015

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelis

4.9
CVE-2026-54242

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox

4.9
CVE-2024-58358

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne

4.9
CVE-2026-8825

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p

4.9
CVE-2026-63734

SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut

4.9
CVE-2026-53594

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Lo

4.9
CVE-2026-15782

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres

4.9
CVE-2026-47008

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that a

4.9
CVE-2026-47023

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.9
CVE-2026-47049

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

4.9
CVE-2026-47052

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that a

4.9
CVE-2026-60145

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported vers

4.9
CVE-2026-60171

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are

4.9
CVE-2026-60194

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality). Supported v

4.9
CVE-2026-60195

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality). Supported v

4.9
CVE-2026-61128

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported vers

4.9
CVE-2026-61144

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported vers

4.9
CVE-2026-65466

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

4.9
CVE-2026-65467

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

4.9
CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to

4.9
CVE-2026-15663

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti

4.9
CVE-2026-66437

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

4.9
CVE-2026-66476

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

4.9
CVE-2026-51564

An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external

4.9
CVE-2026-16811

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas

4.9
CVE-2026-15670

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.9
CVE-2026-15671

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.9
CVE-2026-15444

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the

4.9
CVE-2026-5114

The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and

4.9
CVE-2026-1918

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM

4.9
CVE-2026-15344

The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver

4.9
CVE-2026-11973

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a

4.9
CVE-2026-58156

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe

4.9
CVE-2026-6089

The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor

4.9
CVE-2026-14341

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1

4.9
CVE-2026-14227

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi

4.9
CVE-2026-16105

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin

4.9
CVE-2026-45330

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

4.9
CVE-2026-15403

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame

4.9
CVE-2026-15601

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi

4.9
CVE-2026-15951

The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and

4.9
CVE-2026-16614

The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started