Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 416/436
4.3
CVE-2026-1372

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in

4.3
CVE-2026-65009

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th

4.3
CVE-2026-8285

Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces

4.3
CVE-2026-59850

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok

4.3
CVE-2026-16450

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the

4.3
CVE-2026-16454

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie

4.3
CVE-2026-24232

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data

4.3
CVE-2026-49092

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v

4.3
CVE-2026-63092

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a

4.3
CVE-2026-64821

djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated

4.3
CVE-2026-10675

In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the

4.3
CVE-2026-21954

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi

4.3
CVE-2026-46980

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob

4.3
CVE-2026-60233

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha

4.3
CVE-2026-60303

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

4.3
CVE-2026-60307

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

4.3
CVE-2026-60395

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1

4.3
CVE-2026-60397

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.

4.3
CVE-2026-60408

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op

4.3
CVE-2026-60410

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op

4.3
CVE-2026-60434

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The

4.3
CVE-2026-61292

Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).

4.3
CVE-2026-61315

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar

4.3
CVE-2026-61316

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar

4.3
CVE-2026-62483

Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp

4.3
CVE-2026-65314

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to i

4.3
CVE-2026-16485

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

4.3
CVE-2026-16486

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f

4.3
CVE-2026-63143

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122

4.3
CVE-2026-63145

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification

4.3
CVE-2026-63259

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie

4.3
CVE-2026-63262

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied

4.3
CVE-2026-16473

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud

4.3
CVE-2026-65011

Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de

4.3
CVE-2026-65650

Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

4.3
CVE-2026-13061

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi

4.3
CVE-2026-13063

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem

4.3
CVE-2026-13073

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte

4.3
CVE-2026-24537

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

4.3
CVE-2026-25424

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

4.3
CVE-2026-27392

Contributor Broken Access Control in uListing <= 2.2.0 versions.

4.3
CVE-2026-27423

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

4.3
CVE-2026-61973

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

4.3
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi

4.3
CVE-2026-65456

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

4.3
CVE-2026-65457

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

4.3
CVE-2026-65458

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P

4.3
CVE-2026-65460

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

4.3
CVE-2026-65491

Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.

4.3
CVE-2026-65524

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started