Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 411/454
7.2
CVE-2026-17625

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1

7.2
CVE-2026-70608

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10

7.2
CVE-2026-16636

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo

7.2
CVE-2026-18325

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro

7.2
CVE-2026-18510

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross

7.2
CVE-2026-19034

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s

7.2
CVE-2025-15028

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is

7.2
CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of

7.2
CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp

7.2
CVE-2026-65549

Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.

7.2
CVE-2026-65559

Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.

7.2
CVE-2026-63725

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta

7.2
CVE-2026-13170

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to includ

7.2
CVE-2026-14237

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat

7.2
CVE-2026-4757

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege

7.2
CVE-2026-72747

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject maliciou

7.2
CVE-2026-18635

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able

7.2
CVE-2026-47299

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an aut

7.2
CVE-2026-62910

Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attack

7.2
CVE-2025-59319

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and

7.2
CVE-2026-68752

A Project Resource Manager may gain broader administrative privileges under specific conditions.

7.2
CVE-2026-68759

A holder of a valid integration credential may impersonate other users under specific conditions.

7.2
CVE-2026-12005

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

7.2
CVE-2026-12618

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

7.2
CVE-2026-18146

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

7.2
CVE-2026-6471

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any

7.2
CVE-2026-27380

Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.

7.2
CVE-2026-66704

Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.

7.2
CVE-2026-66256

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects A

7.2
CVE-2026-73670

A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators t

7.2
CVE-2026-19771

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /c

7.2
CVE-2026-18109

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all vers

7.2
CVE-2026-19794

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5

7.2
CVE-2026-72828

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. Th

7.2
CVE-2026-66270

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type

7.2
CVE-2026-66271

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type

7.2
CVE-2026-19628

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify applica

7.2
CVE-2026-73679

ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authentica

7.2
CVE-2026-14433

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site

7.2
CVE-2026-13360

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scriptin

7.2
CVE-2026-16145

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cro

7.2
CVE-2026-15002

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions

7.2
CVE-2026-17533

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionalit

7.2
CVE-2026-17581

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'the

7.2
CVE-2026-18653

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL sta

7.2
CVE-2026-10734

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in al

7.2
CVE-2026-13424

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc

7.2
CVE-2026-2497

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parame

7.2
CVE-2026-74998

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were no

7.2
CVE-2026-16137

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path t

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started