Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 36/42
2.7
CVE-2026-14225

The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-re

2.7
CVE-2026-48074

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

2.7
CVE-2026-16957

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed

2.7
CVE-2026-48412

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att

2.7
CVE-2026-55984

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

2.7
CVE-2026-58445

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

2.7
CVE-2026-58511

Webhook Authorization Header Returned in Plaintext via API

2.7
CVE-2026-17071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traver

2.7
CVE-2026-19837

A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/

2.7
CVE-2026-62684

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

2.7
CVE-2026-13173

The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before ass

2.7
CVE-2026-14825

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa

2.7
CVE-2026-14826

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE

2.7
CVE-2026-19406

The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t

2.7
CVE-2026-76361

In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c

2.7
CVE-2026-76368

In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta

2.7
CVE-2026-76369

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto

2.7
CVE-2026-76371

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r

2.7
CVE-2026-19699

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint

2.7
CVE-2026-16577

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c

2.7
CVE-2026-19085

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic

2.7
CVE-2026-19435

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo

2.7
CVE-2026-66721

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def

2.7
CVE-2026-13176

The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify eve

2.7
CVE-2026-14187

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al

2.7
CVE-2026-77003

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c

2.7
CVE-2026-79777

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p

2.7
CVE-2026-9805

SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size

2.7
CVE-2026-79615

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba

2.7
CVE-2026-77704

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req

2.7
CVE-2026-81200

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa

2.6
CVE-2025-61873

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor

2.6
CVE-2026-27632

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar a

2.6
CVE-2026-21725

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w

2.6
CVE-2025-27769

A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC

2.6
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue

2.6
CVE-2026-32058

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos

2.6
CVE-2025-55274

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo

2.6
CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us

2.6
CVE-2026-7845

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.toby

2.6
CVE-2026-7846

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the

2.6
CVE-2026-7847

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_

2.6
CVE-2025-31957

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t

2.6
CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose

2.6
CVE-2026-6883

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18

2.6
CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may

2.6
CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive

2.6
CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce

2.6
CVE-2026-45154

Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous

2.6
CVE-2026-45155

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 an

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started