Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 364/436
4.7
CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi

4.7
CVE-2026-46772

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF

4.7
CVE-2026-12463

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha

4.7
CVE-2026-39595

Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.

4.7
CVE-2026-44587

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ

4.7
CVE-2026-50267

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati

4.7
CVE-2026-54106

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac

4.7
CVE-2026-48984

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre

4.7
CVE-2026-48986

pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_

4.7
CVE-2026-56332

Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re

4.7
CVE-2026-12789

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec

4.7
CVE-2026-56117

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handl

4.7
CVE-2026-53008

In the Linux kernel, the following vulnerability has been resolved: ice: fix race condition in TX timestamp ring cleanu

4.7
CVE-2026-53108

In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix unmap race with PMD migration entr

4.7
CVE-2026-13034

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com

4.7
CVE-2026-13495

A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi

4.7
CVE-2026-41991

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util

4.7
CVE-2026-13569

A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin

4.7
CVE-2026-57957

Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unau

4.7
CVE-2026-43743

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS

4.7
CVE-2026-3602

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1

4.7
CVE-2026-13812

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a re

4.7
CVE-2026-53352

In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap

4.7
CVE-2026-55595

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

4.7
CVE-2026-14620

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a

4.7
CVE-2026-10659

The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that,

4.7
CVE-2026-12002

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request

4.7
CVE-2026-54344

ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep

4.7
CVE-2026-59883

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar

4.7
CVE-2026-14361

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template

4.7
CVE-2026-59947

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug

4.7
CVE-2026-15173

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

4.7
CVE-2026-57031

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N

4.7
CVE-2026-15494

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/

4.7
CVE-2026-15518

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryControl

4.7
CVE-2026-15533

A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of

4.7
CVE-2026-15539

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi

4.7
CVE-2026-44760

Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave

4.7
CVE-2026-15700

A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th

4.7
CVE-2026-49167

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

4.7
CVE-2026-54432

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus

4.7
CVE-2026-50310

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information

4.7
CVE-2026-50312

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

4.7
CVE-2026-50657

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to

4.7
CVE-2026-50183

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit

4.7
CVE-2026-40106

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p

4.7
CVE-2026-54163

secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th

4.7
CVE-2026-16088

A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of t

4.7
CVE-2026-16226

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings o

4.7
CVE-2026-64823

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started