Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 426/436
4.3
CVE-2026-61422

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. Whe

4.3
CVE-2026-65613

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while lis

4.3
CVE-2026-62313

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte

4.3
CVE-2026-33047

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass

4.3
CVE-2026-53487

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove

4.3
CVE-2026-53541

OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in

4.3
CVE-2026-76057

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

4.3
CVE-2026-76074

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

4.3
CVE-2026-4245

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0

4.3
CVE-2026-4244

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

4.3
CVE-2026-5093

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da

4.3
CVE-2026-78054

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function

4.3
CVE-2026-78055

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vul

4.3
CVE-2026-78059

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of

4.3
CVE-2026-78060

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of t

4.3
CVE-2026-14853

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a

4.3
CVE-2026-77116

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-

4.3
CVE-2026-78145

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/u

4.3
CVE-2026-78186

A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the

4.3
CVE-2026-78280

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

4.3
CVE-2026-21759

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  A

4.3
CVE-2026-78250

A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component

4.3
CVE-2026-78417

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a

4.3
CVE-2026-77923

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in

4.3
CVE-2026-55468

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o

4.3
CVE-2026-10630

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress

4.3
CVE-2026-19801

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera

4.3
CVE-2026-75930

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve

4.3
CVE-2026-78466

The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and

4.3
CVE-2026-78467

The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a

4.3
CVE-2026-75908

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T

4.3
CVE-2026-79669

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read a

4.3
CVE-2026-79406

A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceIm

4.3
CVE-2026-62986

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

4.3
CVE-2026-78895

Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

4.3
CVE-2026-78896

Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-o

4.3
CVE-2026-78908

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

4.3
CVE-2026-78940

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi

4.3
CVE-2026-78942

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

4.3
CVE-2026-78946

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

4.3
CVE-2026-78954

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi

4.3
CVE-2026-78961

Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

4.3
CVE-2026-78962

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

4.3
CVE-2026-78966

Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

4.3
CVE-2026-78976

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had

4.3
CVE-2026-78979

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social

4.3
CVE-2026-78980

Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soc

4.3
CVE-2026-78987

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

4.3
CVE-2026-79000

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote atta

4.3
CVE-2026-79003

Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social en

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started