Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 364/454
7.4
CVE-2026-54429

A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handl

7.4
CVE-2026-54127

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2026-4017

Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause

7.4
CVE-2026-47473

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex

7.4
CVE-2026-48287

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut

7.4
CVE-2026-46513

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T

7.4
CVE-2026-62232

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FAS

7.4
CVE-2026-16404

Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

7.4
CVE-2026-46943

Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported ve

7.4
CVE-2026-47026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).

7.4
CVE-2026-47050

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.4
CVE-2026-47058

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,

7.4
CVE-2026-60179

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are a

7.4
CVE-2026-60317

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are a

7.4
CVE-2026-60667

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The sup

7.4
CVE-2026-60725

Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are aff

7.4
CVE-2026-60823

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver

7.4
CVE-2026-60827

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver

7.4
CVE-2026-61113

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported

7.4
CVE-2026-61135

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th

7.4
CVE-2026-61164

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.4
CVE-2026-61173

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

7.4
CVE-2026-61185

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In

7.4
CVE-2026-61210

Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The s

7.4
CVE-2026-61234

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcureme

7.4
CVE-2026-56820

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug

7.4
CVE-2026-64829

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta

7.4
CVE-2026-66141

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

7.4
CVE-2026-57989

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

7.4
CVE-2026-57990

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

7.4
CVE-2026-59546

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

7.4
CVE-2026-55953

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in

7.4
CVE-2026-14528

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

7.4
CVE-2026-15328

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i

7.4
CVE-2026-56821

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,

7.4
CVE-2026-56822

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,

7.4
CVE-2026-13690

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor log

7.4
CVE-2026-54660

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol

7.4
CVE-2026-13697

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an

7.4
CVE-2026-8497

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0

7.4
CVE-2026-18394

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob

7.4
CVE-2026-51953

An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication

7.4
CVE-2026-18556 KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.

7.4
CVE-2026-67598

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all

7.4
CVE-2026-65802

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat

7.4
CVE-2026-66321

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

7.4
CVE-2026-14838

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc.

7.4
CVE-2026-60007

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P

7.4
CVE-2026-25288

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

7.4
CVE-2026-16443

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started