Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 369/436
4.6
CVE-2026-61456

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1

4.6
CVE-2025-30008

HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users

4.6
CVE-2026-49794

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat

4.6
CVE-2026-55016

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55019

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55020

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55135

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-62826

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-21760

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a

4.6
CVE-2026-53592

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th

4.6
CVE-2026-47689

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.

4.6
CVE-2026-46948

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sec

4.6
CVE-2026-60684

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).

4.6
CVE-2026-7007

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.

4.6
CVE-2026-43753

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO

4.6
CVE-2026-43766

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS

4.6
CVE-2026-64732

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 2

4.6
CVE-2026-16273

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field

4.6
CVE-2026-20471

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service

4.6
CVE-2026-69093

Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe

4.6
CVE-2026-67673

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is

4.6
CVE-2026-47362

In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con

4.6
CVE-2026-21060

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a

4.6
CVE-2026-21070

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensiti

4.6
CVE-2026-66408

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec

4.6
CVE-2026-12051

The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der

4.6
CVE-2026-21269

is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to in

4.6
CVE-2026-61350

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

4.6
CVE-2026-62829

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-62917

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ

4.6
CVE-2026-64897

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-64902

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-64916

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-64922

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2025-59320

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s

4.6
CVE-2026-73428

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to sto

4.6
CVE-2026-12629

The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, th

4.6
CVE-2026-74908

Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exac

4.6
CVE-2026-73426

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cro

4.6
CVE-2026-45119

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate cer

4.6
CVE-2026-45129

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate reque

4.6
CVE-2026-71071

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

4.6
CVE-2026-54793

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Genera

4.6
CVE-2026-61607

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2,

4.6
CVE-2026-72847

broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are c

4.6
CVE-2026-53468

Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Ver

4.6
CVE-2026-75331

tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints i

4.6
CVE-2026-81681

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB

4.6
CVE-2026-73839

Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the r

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started