Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 358/454
7.5
CVE-2026-81699

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing

7.5
CVE-2026-81704

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile

7.5
CVE-2026-81705

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi

7.5
CVE-2026-81718

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect

7.5
CVE-2026-81721

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allo

7.5
CVE-2026-81722

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv

7.5
CVE-2026-37198

An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via suppl

7.5
CVE-2026-59282

Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a

7.5
CVE-2026-76640

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisio

7.5
CVE-2026-77438

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public shar

7.5
CVE-2026-38346

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attacke

7.5
CVE-2026-38348

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denia

7.5
CVE-2026-38349

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attacke

7.5
CVE-2026-38350

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows atta

7.5
CVE-2026-67560

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A

7.5
CVE-2026-73809

A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web manag

7.5
CVE-2026-75418

A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An at

7.5
CVE-2026-75813

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access

7.5
CVE-2026-76940

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout m

7.5
CVE-2026-76945

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An

7.5
CVE-2026-18983

The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all vers

7.5
CVE-2026-19084

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured im

7.5
CVE-2026-5097

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to,

7.5
CVE-2026-80614

In the Linux kernel, the following vulnerability has been resolved: net: emac: Fix NULL pointer dereference in emac_pro

7.5
CVE-2026-80631

In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject compressed segment that overflow

7.5
CVE-2026-80637

In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: fix unaligned memory access in

7.5
CVE-2026-80646

In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_de

7.5
CVE-2026-80691

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iblock: Fix wrong PR ops NULL check f

7.5
CVE-2026-80707

In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): i

7.5
CVE-2026-80717

In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter leng

7.5
CVE-2026-80720

In the Linux kernel, the following vulnerability has been resolved: iomap: add a separate bio_set for iomap_split_ioend

7.5
CVE-2026-27852

An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresse

7.5
CVE-2026-33605

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenti

7.5
CVE-2026-42391

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which

7.5
CVE-2026-82247

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as te

7.5
CVE-2026-82251

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when de

7.5
CVE-2026-82252

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-

7.5
CVE-2026-82253

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule n

7.5
CVE-2026-82254

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-cont

7.5
CVE-2026-82259

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experim

7.5
CVE-2026-82260

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunction

7.5
CVE-2026-82261

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a C

7.5
CVE-2026-37237

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMed

7.5
CVE-2026-37736

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of

7.5
CVE-2026-38636

An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic

7.5
CVE-2026-38638

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic

7.5
CVE-2026-56854

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the P

7.5
CVE-2026-81285

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

7.5
CVE-2026-81767

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

7.5
CVE-2026-54788

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started