Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 377/436
4.4
CVE-2026-71212

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py

4.4
CVE-2026-0637

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert

4.4
CVE-2026-19079

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W

4.4
CVE-2026-11425

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo

4.4
CVE-2026-19326

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the

4.4
CVE-2026-6426

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size

4.4
CVE-2026-20752

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information d

4.4
CVE-2026-73036

Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt

4.4
CVE-2026-47234

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se

4.4
CVE-2026-58420

Local File Inclusion via file:// URI in Migration Restore

4.4
CVE-2026-17438

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper

4.4
CVE-2026-13002

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls

4.4
CVE-2026-2487

The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi

4.4
CVE-2026-12477

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripti

4.4
CVE-2026-75059

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

4.4
CVE-2026-60884

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo

4.4
CVE-2026-71060

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.4
CVE-2026-71139

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

4.4
CVE-2026-71145

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.4
CVE-2026-73880

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

4.4
CVE-2026-16897

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of

4.4
CVE-2026-75526

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 u

4.4
CVE-2026-18822

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrol

4.4
CVE-2026-77643

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and be

4.4
CVE-2026-78196

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn o

4.4
CVE-2026-75982

The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version

4.4
CVE-2026-80101

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validate

4.4
CVE-2026-76149

CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

4.4
CVE-2026-61790

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.4
CVE-2026-21810

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w

4.4
CVE-2026-19454

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup

4.4
CVE-2026-75573

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is suppl

4.4
CVE-2026-81523

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied

4.4
CVE-2026-58616

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E

4.4
CVE-2026-82650

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/mo

4.3
CVE-2025-15405

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results

4.3
CVE-2025-14428

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f

4.3
CVE-2025-69284

Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[

4.3
CVE-2026-21429

Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable

4.3
CVE-2026-0571

A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this

4.3
CVE-2025-15236

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat

4.3
CVE-2025-15237

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat

4.3
CVE-2025-31046

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Co

4.3
CVE-2026-0586

A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown

4.3
CVE-2025-53344

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe

4.3
CVE-2025-65922

PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic

4.3
CVE-2025-64422

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting

4.3
CVE-2025-14441

The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th

4.3
CVE-2025-13812

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is

4.3
CVE-2025-14371

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started