Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 35/42
2.7
CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component con

2.7
CVE-2026-41659

Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (m

2.7
CVE-2026-8200

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc

2.7
CVE-2026-2900

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1

2.7
CVE-2026-5511

In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i

2.7
CVE-2026-8492

Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource L

2.7
CVE-2026-8477

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al

2.7
CVE-2024-47267

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functiona

2.7
CVE-2024-47270

Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo

2.7
CVE-2024-47272

Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and

2.7
CVE-2026-45076

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers

2.7
CVE-2026-10078

A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec

2.7
CVE-2026-44367

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability ex

2.7
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users ca

2.7
CVE-2026-12211

A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of

2.7
CVE-2026-12102

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre

2.7
CVE-2026-10753

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administ

2.7
CVE-2026-49979

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send

2.7
CVE-2026-12755

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows

2.7
CVE-2026-11578

The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to th

2.7
CVE-2026-11781

The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by

2.7
CVE-2026-46466

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

2.7
CVE-2026-27790

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by

2.7
CVE-2026-27844

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated

2.7
CVE-2026-53480

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

2.7
CVE-2026-8800

Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transf

2.7
CVE-2026-6352

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.

2.7
CVE-2026-57961

phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function

2.7
CVE-2026-61971

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu

2.7
CVE-2026-52840

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `ap

2.7
CVE-2026-48329

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypas

2.7
CVE-2026-12906

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r

2.7
CVE-2026-12907

The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,

2.7
CVE-2026-10755

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST

2.7
CVE-2026-11925

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

2.7
CVE-2026-47038

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21

2.7
CVE-2026-61081

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Suppo

2.7
CVE-2026-14821

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out

2.7
CVE-2026-14188

The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of

2.7
CVE-2026-41709

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform

2.7
CVE-2026-14195

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p

2.7
CVE-2026-14214

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr

2.7
CVE-2026-15939

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST

2.7
CVE-2026-15231

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc

2.7
CVE-2026-16274

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action

2.7
CVE-2026-16276

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns

2.7
CVE-2026-16070

The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd

2.7
CVE-2026-16746

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in

2.7
CVE-2026-70430

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as pa

2.7
CVE-2025-15674

The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started