Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 413/454
7.2
CVE-2026-66722

Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack

7.2
CVE-2026-19221

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrator

7.2
CVE-2026-21756

HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to intr

7.2
CVE-2026-71364

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts

7.2
CVE-2026-71904

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerabi

7.2
CVE-2026-71905

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerabil

7.2
CVE-2026-71906

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is c

7.2
CVE-2026-71907

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability i

7.2
CVE-2026-71908

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vul

7.2
CVE-2026-71909

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability

7.2
CVE-2026-71910

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability

7.2
CVE-2026-71911

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is cau

7.2
CVE-2026-71912

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is

7.2
CVE-2026-71913

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vuln

7.2
CVE-2026-71915

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerabil

7.2
CVE-2026-71916

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerab

7.2
CVE-2026-71917

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerabili

7.2
CVE-2026-71918

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulne

7.2
CVE-2026-71919

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerabili

7.2
CVE-2026-71923

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerabilit

7.2
CVE-2026-71924

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability

7.2
CVE-2026-71925

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerabili

7.2
CVE-2026-71926

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerabili

7.2
CVE-2026-71927

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerabili

7.2
CVE-2026-71928

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerabil

7.2
CVE-2026-71929

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerabi

7.2
CVE-2026-71930

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability

7.2
CVE-2026-71931

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab

7.2
CVE-2026-71934

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability

7.2
CVE-2026-71935

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnera

7.2
CVE-2026-71936

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability

7.2
CVE-2026-71937

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vu

7.2
CVE-2026-71938

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnera

7.2
CVE-2026-71939

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. T

7.2
CVE-2026-71940

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function.

7.2
CVE-2026-71941

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerabil

7.2
CVE-2026-71942

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerab

7.2
CVE-2026-71943

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili

7.2
CVE-2026-56703

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not bl

7.2
CVE-2026-18323

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro

7.2
CVE-2026-18328

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based

7.2
CVE-2026-78563

The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu

7.2
CVE-2026-75971

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable

7.2
CVE-2026-75496

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a

7.2
CVE-2026-75497

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin

7.2
CVE-2026-75498

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin

7.2
CVE-2026-45019

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,

7.2
CVE-2026-19760

The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP

7.2
CVE-2026-74851

The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked func

7.2
CVE-2026-18331

The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vul

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started