Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 422/436
4.3
CVE-2026-72912

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec

4.3
CVE-2026-73035

npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t

4.3
CVE-2026-72919

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

4.3
CVE-2026-58244

SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati

4.3
CVE-2026-66761

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s

4.3
CVE-2026-66764

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user

4.3
CVE-2026-66772

SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer

4.3
CVE-2026-66775

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent

4.3
CVE-2026-14549

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

4.3
CVE-2026-19519

A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked

4.3
CVE-2026-72610

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

4.3
CVE-2026-59693

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.

4.3
CVE-2026-72785

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only

4.3
CVE-2026-19078

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the

4.3
CVE-2026-56720

CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that

4.3
CVE-2026-62882

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove

4.3
CVE-2026-18707

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se

4.3
CVE-2026-73229

Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's

4.3
CVE-2026-64934

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho

4.3
CVE-2025-15686

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com

4.3
CVE-2025-15687

A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF

4.3
CVE-2026-13177

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user

4.3
CVE-2026-13612

The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al

4.3
CVE-2026-14857

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his

4.3
CVE-2026-14858

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi

4.3
CVE-2026-14859

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a

4.3
CVE-2026-15388

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

4.3
CVE-2026-18046

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

4.3
CVE-2026-18962

The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int

4.3
CVE-2026-19052

The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac

4.3
CVE-2025-41771

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl

4.3
CVE-2026-47232

Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu

4.3
CVE-2026-66378

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

4.3
CVE-2026-66379

An authenticated user may view private Puppet module metadata without repository read access.

4.3
CVE-2026-66380

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi

4.3
CVE-2026-66382

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

4.3
CVE-2026-68755

A bundle writer may create misleading release promotion information under specific conditions.

4.3
CVE-2026-54183

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas

4.3
CVE-2026-65938

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API

4.3
CVE-2026-70547

An authenticated user without repository read permission may access package metadata under specific conditions.

4.3
CVE-2026-17094

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate

4.3
CVE-2026-18106

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper

4.3
CVE-2026-18144

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

4.3
CVE-2026-17109

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due t

4.3
CVE-2026-17222

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to imp

4.3
CVE-2026-18244

GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2

4.3
CVE-2026-8667

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 1

4.3
CVE-2026-73301

Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/s

4.3
CVE-2026-18148

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log

4.3
CVE-2026-18150

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race c

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started