Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 376/436
4.4
CVE-2026-46388

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr

4.4
CVE-2026-15295

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm

4.4
CVE-2026-3367

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App I

4.4
CVE-2026-9738

The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten

4.4
CVE-2026-11591

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a

4.4
CVE-2026-11898

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions

4.4
CVE-2026-40953

CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers

4.4
CVE-2026-13005

The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip

4.4
CVE-2026-15324

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to St

4.4
CVE-2026-10588

A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management

4.4
CVE-2026-10590

A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar

4.4
CVE-2026-41993

Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc

4.4
CVE-2026-16130

A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of th

4.4
CVE-2026-46671

Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciou

4.4
CVE-2026-12139

Tanium addressed an information disclosure vulnerability in Connect.

4.4
CVE-2026-46936

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions t

4.4
CVE-2026-46991

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise

4.4
CVE-2026-47012

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported vers

4.4
CVE-2026-60177

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported v

4.4
CVE-2026-60182

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported v

4.4
CVE-2026-60184

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.4
CVE-2026-60185

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.4
CVE-2026-60186

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).

4.4
CVE-2026-60187

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.4
CVE-2026-60188

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.4
CVE-2026-60189

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.4
CVE-2026-60601

Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The

4.4
CVE-2026-60713

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

4.4
CVE-2026-61084

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.

4.4
CVE-2026-61191

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Manage

4.4
CVE-2026-15647

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term

4.4
CVE-2026-15786

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v

4.4
CVE-2026-24639

Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

4.4
CVE-2026-65496

Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.

4.4
CVE-2026-15673

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.4
CVE-2026-56850

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli

4.4
CVE-2026-59327

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string

4.4
CVE-2026-20472

In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servic

4.4
CVE-2026-20484

In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local informati

4.4
CVE-2026-20488

In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati

4.4
CVE-2026-20489

In display, there is a possible information disclosure due to an integer overflow. This could lead to local information

4.4
CVE-2026-20490

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic

4.4
CVE-2026-20493

In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servi

4.4
CVE-2026-20496

In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information

4.4
CVE-2026-18508

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin

4.4
CVE-2026-18477

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a

4.4
CVE-2026-17614

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getCo

4.4
CVE-2026-47487

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos

4.4
CVE-2026-5108

The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti

4.4
CVE-2026-5116

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started