Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 424/436
4.3
CVE-2026-19996

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin

4.3
CVE-2026-19998

A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file

4.3
CVE-2026-75004

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled

4.3
CVE-2026-16045

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and person

4.3
CVE-2026-16046

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for f

4.3
CVE-2026-16047

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access

4.3
CVE-2026-16049

Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions w

4.3
CVE-2026-55704

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allo

4.3
CVE-2026-59829

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with cate

4.3
CVE-2026-75046

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

4.3
CVE-2026-12630

Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size

4.3
CVE-2026-71486

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1

4.3
CVE-2026-28984

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.1

4.3
CVE-2026-43795

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7

4.3
CVE-2026-64780

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS

4.3
CVE-2026-64781

The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.

4.3
CVE-2026-64784

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.

4.3
CVE-2026-65331

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65332

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65333

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65334

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.1

4.3
CVE-2026-65335

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65336

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65337

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65338

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7

4.3
CVE-2026-65340

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS

4.3
CVE-2026-65351

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS

4.3
CVE-2026-75077

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

4.3
CVE-2026-75078

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par

4.3
CVE-2026-75081

A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/accoun

4.3
CVE-2026-75082

A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/r

4.3
CVE-2026-75090

A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_ggu

4.3
CVE-2026-75093

A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_al

4.3
CVE-2026-75151

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vu

4.3
CVE-2026-74903

SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which

4.3
CVE-2026-75832

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a

4.3
CVE-2026-75835

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuth

4.3
CVE-2026-75839

ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerabil

4.3
CVE-2026-75841

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticat

4.3
CVE-2026-74971

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Fi

4.3
CVE-2026-74972

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ES

4.3
CVE-2026-66634

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

4.3
CVE-2026-70657

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined

4.3
CVE-2026-74003

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

4.3
CVE-2026-74006

Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

4.3
CVE-2026-45121

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistentl

4.3
CVE-2026-45122

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissio

4.3
CVE-2026-45123

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6

4.3
CVE-2026-45124

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consis

4.3
CVE-2026-47245

MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started