Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 414/454
7.2
CVE-2026-80233

CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability.

7.2
CVE-2026-81031

IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The

7.2
CVE-2026-47836

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN reposito

7.2
CVE-2026-71171

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an

7.2
CVE-2026-13415

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of it

7.2
CVE-2026-19223

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an

7.2
CVE-2026-78271

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

7.2
CVE-2026-78276

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

7.2
CVE-2026-54718

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an

7.2
CVE-2026-75417

A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within applicat

7.2
CVE-2026-18324

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro

7.2
CVE-2026-18978

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all version

7.2
CVE-2026-76053

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross

7.2
CVE-2026-77365

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln

7.2
CVE-2026-14558

The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises use

7.2
CVE-2026-6286

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Script

7.2
CVE-2026-79996

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its lo

7.2
CVE-2026-5934

The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0

7.2
CVE-2026-6176

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregate

7.2
CVE-2026-81757

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

7.2
CVE-2026-75121

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b

7.2
CVE-2026-75122

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b

7.2
CVE-2026-75123

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b

7.1
CVE-2025-69415

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a

7.1
CVE-2026-21447

Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulne

7.1
CVE-2025-68753

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l

7.1
CVE-2023-49186

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Ma

7.1
CVE-2024-30461

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc

7.1
CVE-2024-53735

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We

7.1
CVE-2025-52519

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,

7.1
CVE-2025-61781

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.

7.1
CVE-2024-30547

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea

7.1
CVE-2025-69084

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga

7.1
CVE-2025-69085

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank

7.1
CVE-2025-30631

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerc

7.1
CVE-2025-31642

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU

7.1
CVE-2025-14835

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet

7.1
CVE-2025-32300

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studi

7.1
CVE-2025-69082

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo

7.1
CVE-2025-46494

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove Widget

7.1
CVE-2025-69220

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file

7.1
CVE-2026-21681

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

7.1
CVE-2026-22186

Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsyst

7.1
CVE-2026-21684

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

7.1
CVE-2026-21685

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

7.1
CVE-2026-21686

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

7.1
CVE-2026-21687

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

7.1
CVE-2025-12551

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins ListingH

7.1
CVE-2025-13504

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Real Est

7.1
CVE-2025-22725

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started