Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 408/454
7.2
CVE-2026-59721

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad

7.2
CVE-2026-61343

LibreBooking's email template editor save action passes the submitted template name directly into the destination file p

7.2
CVE-2026-0280

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticat

7.2
CVE-2026-0283

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a

7.2
CVE-2026-0286

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate

7.2
CVE-2026-13430

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and

7.2
CVE-2026-15298

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including,

7.2
CVE-2026-22660

FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administra

7.2
CVE-2026-60091

PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru

7.2
CVE-2026-1667

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip

7.2
CVE-2026-53448

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe

7.2
CVE-2026-13114

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti

7.2
CVE-2026-3576

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local

7.2
CVE-2026-13378

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac

7.2
CVE-2026-6939

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app

7.2
CVE-2026-57372

Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.

7.2
CVE-2026-57407

Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Se

7.2
CVE-2026-59521

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Inj

7.2
CVE-2026-62643

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM

7.2
CVE-2026-54433

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai

7.2
CVE-2026-15410 KEV

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S

7.2
CVE-2026-47992

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu

7.2
CVE-2026-20297

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below

7.2
CVE-2026-62350

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit

7.2
CVE-2026-13042

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions

7.2
CVE-2026-7543

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions

7.2
CVE-2026-44982

CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe

7.2
CVE-2026-15395

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting

7.2
CVE-2026-51082

A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager be

7.2
CVE-2026-14448

An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi

7.2
CVE-2026-6952

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B

7.2
CVE-2026-1771

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi

7.2
CVE-2026-63453

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab

7.2
CVE-2026-63454

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an

7.2
CVE-2026-44878

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r

7.2
CVE-2026-44879

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta

7.2
CVE-2026-46954

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supporte

7.2
CVE-2026-46981

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob

7.2
CVE-2026-46988

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector

7.2
CVE-2026-47005

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Updat

7.2
CVE-2026-47006

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Updat

7.2
CVE-2026-60153

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported version

7.2
CVE-2026-60245

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

7.2
CVE-2026-60316

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versi

7.2
CVE-2026-60335

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.2
CVE-2026-60340

Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center).

7.2
CVE-2026-60345

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supporte

7.2
CVE-2026-60396

Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected ar

7.2
CVE-2026-60418

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

7.2
CVE-2026-60466

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started