Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 357/454
7.5
CVE-2026-74741

In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix NULL pointer dereference in non-MSI-

7.5
CVE-2026-74742

In the Linux kernel, the following vulnerability has been resolved: veth: fix queue index used to wake the peer txq in

7.5
CVE-2026-74745

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: avoid deadlock when canceling IRQ affini

7.5
CVE-2026-74750

In the Linux kernel, the following vulnerability has been resolved: ovpn: defer key slot crypto freeing to workqueue K

7.5
CVE-2026-80520

In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key

7.5
CVE-2026-80527

In the Linux kernel, the following vulnerability has been resolved: ceph: fix hanging __ceph_get_caps() with stale mds_

7.5
CVE-2026-80588

In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path

7.5
CVE-2025-61162

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req

7.5
CVE-2025-61164

Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.

7.5
CVE-2026-36851

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

7.5
CVE-2026-26446

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was alread

7.5
CVE-2026-26447

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same

7.5
CVE-2026-26449

In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null poi

7.5
CVE-2026-46369

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through

7.5
CVE-2026-68863

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthentica

7.5
CVE-2025-51675

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c

7.5
CVE-2025-61478

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2025-61479

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2025-61480

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2026-75328

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitra

7.5
CVE-2026-75333

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new F

7.5
CVE-2026-47851

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.

7.5
CVE-2026-47852

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.

7.5
CVE-2026-19715

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it

7.5
CVE-2026-47885

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -

7.5
CVE-2026-47886

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of

7.5
CVE-2026-47888

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spr

7.5
CVE-2026-47889

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite att

7.5
CVE-2026-47893

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by inc

7.5
CVE-2026-78137

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthen

7.5
CVE-2026-75005

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at

7.5
CVE-2026-80433

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

7.5
CVE-2026-81575

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which con

7.5
CVE-2026-30046

A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of S

7.5
CVE-2026-30047

A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers

7.5
CVE-2026-30050

An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows atta

7.5
CVE-2026-30056

A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of

7.5
CVE-2026-30057

An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS)

7.5
CVE-2026-30062

An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU

7.5
CVE-2026-5680

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket

7.5
CVE-2026-78002

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `

7.5
CVE-2026-80212

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource:

7.5
CVE-2026-81335

Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch

7.5
CVE-2026-81678

AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extr

7.5
CVE-2026-81688

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metada

7.5
CVE-2026-81689

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th

7.5
CVE-2026-81691

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting

7.5
CVE-2026-81692

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples f

7.5
CVE-2026-81693

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attack

7.5
CVE-2026-81698

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started