Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 356/436
4.8
CVE-2026-53624

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/hel

4.8
CVE-2026-54800

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst

4.8
CVE-2026-55890

Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media

4.8
CVE-2026-56666

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch

4.8
CVE-2026-57476

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio

4.8
CVE-2026-55481

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related br

4.8
CVE-2026-57213

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_manag

4.8
CVE-2026-13237

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version

4.8
CVE-2026-13238

Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a

4.8
CVE-2026-13243

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue

4.8
CVE-2026-56763

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na

4.8
CVE-2026-12478

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block

4.8
CVE-2026-50684

Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Serv

4.8
CVE-2026-47999

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege

4.8
CVE-2026-56353

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu

4.8
CVE-2026-58557

Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availab

4.8
CVE-2026-1562

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user

4.8
CVE-2026-1563

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u

4.8
CVE-2026-48819

Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa

4.8
CVE-2026-55254

NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src

4.8
CVE-2026-10724

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review

4.8
CVE-2026-26081

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise

4.8
CVE-2026-15812

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34).

4.8
CVE-2026-60351

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t

4.8
CVE-2026-61056

Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported

4.8
CVE-2026-61057

Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). Th

4.8
CVE-2026-61247

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp

4.8
CVE-2026-56416

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSI

4.8
CVE-2026-63281

Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul

4.8
CVE-2026-9577

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref

4.8
CVE-2026-65531

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

4.8
CVE-2026-66139

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

4.8
CVE-2026-14203

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML

4.8
CVE-2026-63237

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s

4.8
CVE-2026-65325

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n

4.8
CVE-2026-65100

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so

4.8
CVE-2026-66400

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh

4.8
CVE-2026-16729

undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before

4.8
CVE-2026-16728

undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to

4.8
CVE-2026-13344

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta

4.8
CVE-2026-63220

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For

4.8
CVE-2026-54706

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

4.8
CVE-2025-15669

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren

4.8
CVE-2025-15675

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor

4.8
CVE-2026-56609

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using

4.8
CVE-2026-67612

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al

4.8
CVE-2026-67617

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al

4.8
CVE-2026-14824

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp

4.8
CVE-2026-15233

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at

4.8
CVE-2026-70589

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started