Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 366/454
7.4
CVE-2026-62492

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security).

7.4
CVE-2026-62538

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

7.4
CVE-2026-70672

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

7.4
CVE-2026-70699

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi

7.4
CVE-2026-70734

Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affec

7.4
CVE-2026-70779

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo

7.4
CVE-2026-70783

Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp

7.4
CVE-2026-70790

Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Interna

7.4
CVE-2026-70823

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.4
CVE-2026-70898

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu

7.4
CVE-2026-71009

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.4
CVE-2026-71143

Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Thi

7.4
CVE-2026-75984

A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admi

7.4
CVE-2026-75985

A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/pin

7.4
CVE-2026-58088

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program h

7.4
CVE-2026-76213

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure count

7.4
CVE-2026-76214

phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAut

7.4
CVE-2026-62669

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login

7.4
CVE-2026-16851

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a use-af

7.4
CVE-2026-76582

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-

7.4
CVE-2026-76583

A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functional

7.4
CVE-2025-36254

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attac

7.4
CVE-2026-76362

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOA

7.4
CVE-2026-76403

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or a

7.4
CVE-2026-76591

A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of

7.4
CVE-2026-19611

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can coll

7.4
CVE-2026-77004

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?met

7.4
CVE-2026-77031

A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the fil

7.4
CVE-2026-62960

Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bun

7.4
CVE-2026-53525

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay au

7.4
CVE-2026-77945

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.

7.4
CVE-2026-78122

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en

7.4
CVE-2026-78063

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the

7.4
CVE-2026-78141

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCo

7.4
CVE-2026-78156

A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air

7.4
CVE-2026-78157

A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-pat

7.4
CVE-2026-10582

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects

7.4
CVE-2026-21751

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized

7.4
CVE-2026-76844

webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against

7.4
CVE-2026-76072

The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende

7.4
CVE-2026-56135

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/sec

7.4
CVE-2026-53561

An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0

7.4
CVE-2026-79664

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintai

7.4
CVE-2026-79286

Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to po

7.4
CVE-2026-41707

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDec

7.4
CVE-2026-54550

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and

7.4
CVE-2026-47841

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distr

7.4
CVE-2026-18717

ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker

7.4
CVE-2026-40018

None None None No publicly available exploits are known.

7.4
CVE-2026-73208

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started