Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 428/436
4.3
CVE-2026-79217

Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass

4.3
CVE-2026-79222

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to

4.3
CVE-2026-79225

Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever

4.3
CVE-2026-79233

UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to sp

4.3
CVE-2026-79237

Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web or

4.3
CVE-2026-79238

Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging so

4.3
CVE-2026-79248

Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-79251

Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially by

4.3
CVE-2026-79252

Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-orig

4.3
CVE-2026-79254

Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta

4.3
CVE-2026-79259

Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass sy

4.3
CVE-2026-79261

Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web orig

4.3
CVE-2026-79262

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi

4.3
CVE-2026-79264

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass we

4.3
CVE-2026-79267

Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rend

4.3
CVE-2026-79269

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass

4.3
CVE-2026-79273

Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacke

4.3
CVE-2026-79274

Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data vi

4.3
CVE-2026-79276

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging

4.3
CVE-2026-79284

UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had comprom

4.3
CVE-2026-79793

A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown

4.3
CVE-2026-80194

Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_pro

4.3
CVE-2026-80197

Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints

4.3
CVE-2026-74930

The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the

4.3
CVE-2026-77789

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to th

4.3
CVE-2026-79654

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a

4.3
CVE-2026-15387

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3

4.3
CVE-2026-54614

DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feat

4.3
CVE-2026-41262

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read

4.3
CVE-2026-71172

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low

4.3
CVE-2026-75601

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instan

4.3
CVE-2026-55227

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s

4.3
CVE-2026-62249

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.3
CVE-2026-47850

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP

4.3
CVE-2026-16568

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

4.3
CVE-2026-16569

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

4.3
CVE-2026-78138

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sal

4.3
CVE-2026-78139

The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one

4.3
CVE-2026-5218

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Techno

4.3
CVE-2026-59280

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a control

4.3
CVE-2026-80209

The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes

4.3
CVE-2026-59319

RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w

4.3
CVE-2026-79995

The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email c

4.3
CVE-2026-9491

A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote au

4.3
CVE-2026-33263

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused b

4.3
CVE-2026-33607

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of

4.3
CVE-2026-40013

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an

4.3
CVE-2026-40015

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands

4.3
CVE-2026-42008

Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentica

4.3
CVE-2026-42392

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to b

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started