Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 420/436
4.3
CVE-2026-23981

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd

4.3
CVE-2026-10569

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug

4.3
CVE-2026-67528

OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol

4.3
CVE-2026-67529

OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap

4.3
CVE-2026-55495

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W

4.3
CVE-2026-55496

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi

4.3
CVE-2026-55499

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri

4.3
CVE-2026-12376

The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing

4.3
CVE-2026-14847

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i

4.3
CVE-2026-14929

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo

4.3
CVE-2026-28144

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti

4.3
CVE-2026-67350

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re

4.3
CVE-2025-62347

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and

4.3
CVE-2026-13729

The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat

4.3
CVE-2025-14469

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,

4.3
CVE-2026-2916

The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an

4.3
CVE-2026-10782

The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin

4.3
CVE-2026-67302

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire

4.3
CVE-2026-67303

FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce

4.3
CVE-2026-67344

ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP

4.3
CVE-2026-11872

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in

4.3
CVE-2026-14938

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be

4.3
CVE-2026-16042

The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin

4.3
CVE-2026-16291

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo

4.3
CVE-2026-18585

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 a

4.3
CVE-2026-15260

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in

4.3
CVE-2026-16289

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending me

4.3
CVE-2026-16564

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order

4.3
CVE-2026-16565

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc

4.3
CVE-2026-69094

Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu

4.3
CVE-2026-62354

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit

4.3
CVE-2026-67616

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi

4.3
CVE-2026-18721

A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file

4.3
CVE-2026-12698

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei

4.3
CVE-2026-16035

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP

4.3
CVE-2026-16056

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler

4.3
CVE-2026-16295

The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p

4.3
CVE-2026-16546

The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA

4.3
CVE-2026-70484

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac

4.3
CVE-2026-70488

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync

4.3
CVE-2026-18819

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul

4.3
CVE-2026-18903

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so

4.3
CVE-2026-16613

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable

4.3
CVE-2026-17515

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio

4.3
CVE-2026-55996

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com

4.3
CVE-2026-7105

The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on

4.3
CVE-2026-71240

DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta

4.3
CVE-2026-71246

Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s

4.3
CVE-2026-71250

Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex

4.3
CVE-2026-15656

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started