Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 383/1152
7.7
CVE-2026-70894

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu

7.7
CVE-2026-70942

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.7
CVE-2026-70945

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

7.7
CVE-2026-70988

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.7
CVE-2026-71056

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).

7.7
CVE-2026-71141

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.7
CVE-2026-76225

ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation th

7.7
CVE-2026-16819

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise d

7.7
CVE-2026-53549

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

7.7
CVE-2026-54493

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation

7.7
CVE-2026-75569

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without

7.7
CVE-2026-76344

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

7.7
CVE-2026-73137

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A te

7.7
CVE-2026-17003

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integr

7.7
CVE-2026-17024

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper ce

7.7
CVE-2026-17423

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a

7.7
CVE-2026-69855

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information o

7.7
CVE-2026-73267

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissi

7.7
CVE-2026-55621

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for

7.7
CVE-2026-55622

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for

7.7
CVE-2026-54457

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e

7.7
CVE-2026-34948

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are pr

7.7
CVE-2026-71366

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Matterm

7.7
CVE-2026-56707

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects

7.7
CVE-2026-19851

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attack

7.7
CVE-2026-79659

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses un

7.7
CVE-2026-79245

Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer p

7.7
CVE-2026-57171

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions

7.7
CVE-2026-75797

The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesyste

7.7
CVE-2026-61792

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

7.7
CVE-2026-61617

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13

7.7
CVE-2026-47879

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto de

7.7
CVE-2026-77017

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine t

7.7
CVE-2026-81576

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on

7.7
CVE-2026-81679

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST AP

7.7
CVE-2026-75889

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor reso

7.7
CVE-2026-82242

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpo

7.7
CVE-2026-81490

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling

7.7
CVE-2026-41012

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vC

7.7
CVE-2026-16600

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does

7.6
CVE-2025-36589

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul

7.6
CVE-2026-22230

OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access fu

7.6
CVE-2025-69195

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo

7.6
CVE-2025-59057

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0

7.6
CVE-2025-71100

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9

7.6
CVE-2026-1008

A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient ser

7.6
CVE-2026-1007

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny

7.6
CVE-2025-27380

HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attac

7.6
CVE-2025-67967

Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configu

7.6
CVE-2025-68057

Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting I

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started