Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 365/454
7.4
CVE-2026-16442

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti

7.4
CVE-2026-70604

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10

7.4
CVE-2026-8470

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's

7.4
CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

7.4
CVE-2026-19139

Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-le

7.4
CVE-2026-48079

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

7.4
CVE-2026-48084

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri

7.4
CVE-2026-72584

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac

7.4
CVE-2026-15554

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti

7.4
CVE-2026-15563

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing

7.4
CVE-2026-50236

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are

7.4
CVE-2026-50237

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t

7.4
CVE-2026-20739

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may

7.4
CVE-2026-20741

Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial

7.4
CVE-2026-20795

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers m

7.4
CVE-2026-22887

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow

7.4
CVE-2026-58612

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information

7.4
CVE-2026-73086

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the na

7.4
CVE-2026-67558

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match aga

7.4
CVE-2026-48551

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a sel

7.4
CVE-2026-11923

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

7.4
CVE-2026-67579

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter

7.4
CVE-2026-73495

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42

7.4
CVE-2026-28189

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.

7.4
CVE-2026-49857

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implem

7.4
CVE-2026-53793

rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended in

7.4
CVE-2026-70452

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent host

7.4
CVE-2026-73655

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStr

7.4
CVE-2026-74356

In the Linux kernel, the following vulnerability has been resolved: vhost: fix vhost_get_avail_idx for a non empty ring

7.4
CVE-2026-19960

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file

7.4
CVE-2026-19962

A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /gofo

7.4
CVE-2026-19963

A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /go

7.4
CVE-2026-19980

A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, M

7.4
CVE-2026-19981

A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500

7.4
CVE-2026-19982

A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code o

7.4
CVE-2026-18534

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing att

7.4
CVE-2026-59825

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12,

7.4
CVE-2026-66635

Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.

7.4
CVE-2026-75912

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers

7.4
CVE-2026-50577

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

7.4
CVE-2026-70666

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/

7.4
CVE-2026-60759

Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Opera

7.4
CVE-2026-60766

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are

7.4
CVE-2026-60792

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v

7.4
CVE-2026-60797

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are

7.4
CVE-2026-60803

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions th

7.4
CVE-2026-60820

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are

7.4
CVE-2026-60856

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packaging).

7.4
CVE-2026-60915

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.4
CVE-2026-60933

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started