Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 391/454
7.3
CVE-2026-61136

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th

7.3
CVE-2026-61267

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loadi

7.3
CVE-2026-61271

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachm

7.3
CVE-2026-16632

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib

7.3
CVE-2026-16796

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo

7.3
CVE-2026-16765

A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality o

7.3
CVE-2026-16519

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on

7.3
CVE-2026-10033

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,

7.3
CVE-2026-59535

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

7.3
CVE-2026-64550

In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: validate MAP frame length bef

7.3
CVE-2026-62432

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct

7.3
CVE-2026-62433

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation

7.3
CVE-2026-8164

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk

7.3
CVE-2026-14893

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core

7.3
CVE-2026-23904

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re

7.3
CVE-2026-65947

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

7.3
CVE-2026-15144

@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec

7.3
CVE-2025-67405

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param

7.3
CVE-2025-67406

https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu

7.3
CVE-2025-67407

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters

7.3
CVE-2025-67408

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter

7.3
CVE-2025-69944

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie

7.3
CVE-2025-69945

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.

7.3
CVE-2025-69949

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em

7.3
CVE-2026-16527

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endp

7.3
CVE-2026-11980

IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.

7.3
CVE-2026-54737

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to

7.3
CVE-2026-18481

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticate

7.3
CVE-2026-4793

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wr

7.3
CVE-2026-18641

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by

7.3
CVE-2026-18647

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue

7.3
CVE-2026-42169

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f

7.3
CVE-2026-18755

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di

7.3
CVE-2026-18770

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un

7.3
CVE-2026-18788

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown fun

7.3
CVE-2026-18810

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard

7.3
CVE-2026-18854

A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element

7.3
CVE-2026-18859

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/u

7.3
CVE-2026-6079

The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing

7.3
CVE-2026-25703

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio

7.3
CVE-2026-71226

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm

7.3
CVE-2026-18958

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a

7.3
CVE-2026-18969

A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is

7.3
CVE-2026-18970

A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen

7.3
CVE-2026-18973

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz

7.3
CVE-2026-18990

A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o

7.3
CVE-2026-18991

A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c

7.3
CVE-2026-19000

A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/

7.3
CVE-2026-19009

A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core

7.3
CVE-2026-19010

A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started