Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 392/454
7.3
CVE-2026-19021

A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi

7.3
CVE-2026-65541

Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.

7.3
CVE-2026-19062

A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unkn

7.3
CVE-2026-19196

A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the

7.3
CVE-2026-19211

A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia

7.3
CVE-2026-11430

Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu

7.3
CVE-2026-19231

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects

7.3
CVE-2026-48098

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers

7.3
CVE-2026-19263

A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem

7.3
CVE-2026-19342

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /i

7.3
CVE-2026-19343

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown function

7.3
CVE-2026-19344

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown funct

7.3
CVE-2026-19351

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the

7.3
CVE-2026-19355

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of

7.3
CVE-2026-19374

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affect

7.3
CVE-2026-19376

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o

7.3
CVE-2026-19379

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of t

7.3
CVE-2026-19384

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unkno

7.3
CVE-2026-65948

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option f

7.3
CVE-2026-68134

In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only reg

7.3
CVE-2026-68230

In the Linux kernel, the following vulnerability has been resolved: media: amlogic-c3: Add validations for ae and awb c

7.3
CVE-2026-68265

In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_

7.3
CVE-2026-68320

In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_au

7.3
CVE-2026-6374

Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab

7.3
CVE-2026-59091

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t

7.3
CVE-2026-44764

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated

7.3
CVE-2026-44765

Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated

7.3
CVE-2026-18639

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s

7.3
CVE-2026-20890

Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Proc

7.3
CVE-2026-59119

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

7.3
CVE-2026-62914

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

7.3
CVE-2026-64900

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.3
CVE-2026-68821

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

7.3
CVE-2026-70355

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.3
CVE-2026-71383

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul

7.3
CVE-2026-67260

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the

7.3
CVE-2026-13476

IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands wit

7.3
CVE-2026-28188

Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.

7.3
CVE-2026-63424

During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could all

7.3
CVE-2026-19710

A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unkn

7.3
CVE-2026-14875

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when install

7.3
CVE-2026-72658

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62

7.3
CVE-2026-72677

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path T

7.3
CVE-2026-73669

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interface

7.3
CVE-2026-17099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authenticatio

7.3
CVE-2026-18511

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the

7.3
CVE-2026-19753

A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of t

7.3
CVE-2026-19757

A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAn

7.3
CVE-2026-19758

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the fil

7.3
CVE-2026-19762

A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file Fi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started