Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 429/436
4.3
CVE-2026-42395

A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process

4.3
CVE-2026-82111

A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of

4.3
CVE-2026-82257

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi

4.3
CVE-2026-81284

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

4.3
CVE-2026-81299

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

4.3
CVE-2026-81761

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

4.3
CVE-2026-55064

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin

4.3
CVE-2026-55547

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from

4.3
CVE-2026-55566

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext

4.3
CVE-2026-55834

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0,

4.3
CVE-2026-66798

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

4.3
CVE-2026-18545

IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat

4.3
CVE-2026-55696

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se

4.3
CVE-2026-80311

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th

4.3
CVE-2026-81346

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX

4.3
CVE-2026-82633

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API

4.3
CVE-2026-82544

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th

4.3
CVE-2026-82658

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authent

4.3
CVE-2026-82552

A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown

4.3
CVE-2026-82554

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_c

4.3
CVE-2026-82587

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_m

4.3
CVE-2026-82588

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/na

4.3
CVE-2026-82589

A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_

4.3
CVE-2026-82590

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of t

4.3
CVE-2026-82601

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a mani

4.3
CVE-2026-82604

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language M

4.2
CVE-2025-68492

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln

4.2
CVE-2025-43904

In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user

4.2
CVE-2026-21922

Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th

4.2
CVE-2026-21979

Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th

4.2
CVE-2026-23955

EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated

4.2
CVE-2026-1484

A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of inte

4.2
CVE-2025-55095

The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W

4.2
CVE-2025-13986

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality

4.2
CVE-2026-1554

XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Priv

4.2
CVE-2026-0598

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. Th

4.2
CVE-2026-2010

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function P

4.2
CVE-2025-62439

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS

4.2
CVE-2026-2802

Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

4.2
CVE-2025-1787

Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr

4.2
CVE-2026-3429

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to

4.2
CVE-2026-32719

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

4.2
CVE-2026-33720

n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` e

4.2
CVE-2026-33248

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1

4.2
CVE-2025-55269

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak

4.2
CVE-2026-26071

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurre

4.2
CVE-2026-26072

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona

4.2
CVE-2026-27814

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race (C++ UB) triggered by an A 1-phas

4.2
CVE-2026-3532

Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.

4.2
CVE-2026-5107

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started