Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 350/436
4.9
CVE-2026-17555

The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers

4.9
CVE-2025-15673

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an

4.9
CVE-2026-69090

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm

4.9
CVE-2026-18103

A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program

4.9
CVE-2026-5062

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre

4.9
CVE-2026-11920

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL

4.9
CVE-2026-11969

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete

4.9
CVE-2026-5651

The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a

4.9
CVE-2026-71283

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile

4.9
CVE-2024-8995

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a

4.9
CVE-2026-17018

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric

4.9
CVE-2026-24329

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i

4.9
CVE-2026-48384

ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi

4.9
CVE-2026-58429

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

4.9
CVE-2026-67613

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitra

4.9
CVE-2026-73304

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id

4.9
CVE-2026-12743

The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-base

4.9
CVE-2026-72820

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directori

4.9
CVE-2026-19631

A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbit

4.9
CVE-2026-16094

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ

4.9
CVE-2026-16146

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ

4.9
CVE-2026-15602

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the

4.9
CVE-2026-15351

The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to

4.9
CVE-2026-17582

The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7

4.9
CVE-2026-2283

The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u

4.9
CVE-2026-17604

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa

4.9
CVE-2026-73383

Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.

4.9
CVE-2026-68924

MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/vie

4.9
CVE-2026-74046

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.

4.9
CVE-2026-55164

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password direc

4.9
CVE-2026-71085

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.9
CVE-2026-44253

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 an

4.9
CVE-2026-76957

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur

4.9
CVE-2026-55489

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentation

4.9
CVE-2026-70656

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

4.9
CVE-2026-59809

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, a

4.9
CVE-2026-60083

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to

4.9
CVE-2026-78277

Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.

4.9
CVE-2026-71920

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vul

4.9
CVE-2026-71932

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulne

4.9
CVE-2026-77824

The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' p

4.9
CVE-2026-79773

Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows auth

4.9
CVE-2026-81028

ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not

4.9
CVE-2026-63179

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, au

4.9
CVE-2026-47894

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configure

4.9
CVE-2026-81272

Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.

4.9
CVE-2026-18374

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the

4.9
CVE-2026-75125

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /c

4.9
CVE-2026-75126

PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities

4.9
CVE-2026-77217

PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer derefere

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started