Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 410/454
7.2
CVE-2026-59764

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu

7.2
CVE-2026-61376

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.

7.2
CVE-2026-13440

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for

7.2
CVE-2026-54605

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth:

7.2
CVE-2026-12476

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3

7.2
CVE-2026-24033

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server.

7.2
CVE-2026-13425

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al

7.2
CVE-2026-16597

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr

7.2
CVE-2026-16655

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

7.2
CVE-2026-18255

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo

7.2
CVE-2026-12357

Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability

7.2
CVE-2026-67244

A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user

7.2
CVE-2026-15397

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and

7.2
CVE-2026-13392

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a

7.2
CVE-2026-16843

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio

7.2
CVE-2026-38710

TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock in

7.2
CVE-2026-13157

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import

7.2
CVE-2026-13158

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impo

7.2
CVE-2026-15244

The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before con

7.2
CVE-2026-15052

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr

7.2
CVE-2026-67333

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi

7.2
CVE-2026-67340

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b

7.2
CVE-2026-67608

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti

7.2
CVE-2026-39931

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t

7.2
CVE-2026-61523

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated

7.2
CVE-2026-61524

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th

7.2
CVE-2026-67599

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke

7.2
CVE-2026-69246

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and

7.2
CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions

7.2
CVE-2026-14818

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi

7.2
CVE-2026-67243

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig

7.2
CVE-2026-18811

A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Perfo

7.2
CVE-2026-18812

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Ex

7.2
CVE-2026-18813

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipul

7.2
CVE-2026-18814

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th

7.2
CVE-2026-18900

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co

7.2
CVE-2026-18901

A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e

7.2
CVE-2026-16143

The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting v

7.2
CVE-2026-18902

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/

7.2
CVE-2026-16605

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to

7.2
CVE-2026-54416

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i

7.2
CVE-2026-6020

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action

7.2
CVE-2026-7693

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.

7.2
CVE-2026-71232

MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template

7.2
CVE-2026-18933

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri

7.2
CVE-2026-71269

Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-

7.2
CVE-2026-71284

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir

7.2
CVE-2026-71292

Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th

7.2
CVE-2026-17506

The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr

7.2
CVE-2026-17630

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started