Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 355/454
7.5
CVE-2026-71862

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

7.5
CVE-2026-63462

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation e

7.5
CVE-2026-27462

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/inval

7.5
CVE-2026-27490

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being

7.5
CVE-2026-30866

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensit

7.5
CVE-2026-63421

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core

7.5
CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in o

7.5
CVE-2026-77781

Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS a

7.5
CVE-2026-59256

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens witho

7.5
CVE-2026-62243

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable

7.5
CVE-2026-62380

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain nul

7.5
CVE-2026-2996

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Valida

7.5
CVE-2026-62384

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read

7.5
CVE-2026-62388

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa

7.5
CVE-2026-63312

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E

7.5
CVE-2026-66393

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at

7.5
CVE-2026-74598

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validatio

7.5
CVE-2026-74621

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix sk_buff leak when the header

7.5
CVE-2026-74624

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: defer invalid log until af

7.5
CVE-2026-74625

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: release template ct on non-IP pa

7.5
CVE-2026-74626

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocat

7.5
CVE-2026-74678

In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: fix skb leak in ax88179_tx_

7.5
CVE-2026-74692

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() a

7.5
CVE-2026-74695

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst bef

7.5
CVE-2026-74696

In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport m

7.5
CVE-2026-74717

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error T

7.5
CVE-2026-47895

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no

7.5
CVE-2026-4671

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkificatio

7.5
CVE-2026-9769

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During Ju

7.5
CVE-2026-78206

exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, tot

7.5
CVE-2026-78208

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate

7.5
CVE-2026-78212

4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remot

7.5
CVE-2026-75899

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parse

7.5
CVE-2026-75931

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit

7.5
CVE-2026-75975

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6

7.5
CVE-2026-76172

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never

7.5
CVE-2026-28153

Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS,

7.5
CVE-2026-28167

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

7.5
CVE-2026-66585

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

7.5
CVE-2026-76848

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validati

7.5
CVE-2025-68825

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta

7.5
CVE-2026-21752

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or

7.5
CVE-2026-66907

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

7.5
CVE-2026-66908

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:

7.5
CVE-2026-71922

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cg

7.5
CVE-2026-75371

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-

7.5
CVE-2026-75368

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause

7.5
CVE-2026-76098

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS throu

7.5
CVE-2026-77384

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh pa

7.5
CVE-2026-78268

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Tel

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started