Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 356/454
7.5
CVE-2026-66766

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vu

7.5
CVE-2026-56709

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token

7.5
CVE-2026-72700

The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation

7.5
CVE-2026-76846

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access

7.5
CVE-2026-78677

GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary g

7.5
CVE-2026-78681

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations

7.5
CVE-2026-78682

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l

7.5
CVE-2026-67578

FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network

7.5
CVE-2026-78576

The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insuff

7.5
CVE-2026-79658

Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware

7.5
CVE-2026-14457

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key

7.5
CVE-2026-18798

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial pac

7.5
CVE-2026-54874

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far

7.5
CVE-2026-63072

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but t

7.5
CVE-2026-63075

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not ack

7.5
CVE-2026-63076

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was no

7.5
CVE-2026-55525

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the init

7.5
CVE-2021-47996

Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, w

7.5
CVE-2022-50998

Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE

7.5
CVE-2023-54354

Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vu

7.5
CVE-2026-79770

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokeniz

7.5
CVE-2026-19913

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation

7.5
CVE-2026-55553

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio

7.5
CVE-2026-71360

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

7.5
CVE-2026-71442

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a

7.5
CVE-2026-71443

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de

7.5
CVE-2026-55620

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well

7.5
CVE-2026-55099

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Comp

7.5
CVE-2026-74932

The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs o

7.5
CVE-2026-65097

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download

7.5
CVE-2026-78901

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside

7.5
CVE-2026-78906

Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra

7.5
CVE-2026-78915

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten

7.5
CVE-2026-79083

Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker w

7.5
CVE-2026-79139

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who h

7.5
CVE-2026-79216

Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende

7.5
CVE-2026-65927

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing t

7.5
CVE-2026-68763

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w

7.5
CVE-2026-18259

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token

7.5
CVE-2026-80191

GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated use

7.5
CVE-2026-80196

Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after passwo

7.5
CVE-2026-80198

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allo

7.5
CVE-2026-74928

The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing

7.5
CVE-2026-18884

The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Par

7.5
CVE-2026-16444

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authen

7.5
CVE-2026-80347

mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSa

7.5
CVE-2026-80205

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear

7.5
CVE-2026-15990

The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.

7.5
CVE-2026-19271

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Sof

7.5
CVE-2026-73108

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started