Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 431/454
7.1
CVE-2026-53842

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influ

7.1
CVE-2026-53846

OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files

7.1
CVE-2026-53858

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY c

7.1
CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate

7.1
CVE-2026-53865

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-der

7.1
CVE-2026-46914

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a

7.1
CVE-2026-46932

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operatio

7.1
CVE-2024-49269

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

7.1
CVE-2025-31013

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow

7.1
CVE-2025-59560

Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.

7.1
CVE-2025-69104

Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.

7.1
CVE-2025-69151

Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions.

7.1
CVE-2026-22328

Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.

7.1
CVE-2026-22329

Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions.

7.1
CVE-2026-22339

Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.

7.1
CVE-2026-39548

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

7.1
CVE-2026-39597

Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.

7.1
CVE-2026-40765

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

7.1
CVE-2026-41557

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

7.1
CVE-2026-42385

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

7.1
CVE-2026-48869

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

7.1
CVE-2026-49074

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.

7.1
CVE-2026-49778

Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

7.1
CVE-2026-54188

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

7.1
CVE-2026-54189

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

7.1
CVE-2026-54192

Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

7.1
CVE-2026-54195

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

7.1
CVE-2026-8089

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin

7.1
CVE-2026-9570

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline

7.1
CVE-2025-68524

Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

7.1
CVE-2025-69140

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

7.1
CVE-2026-10641

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont

7.1
CVE-2026-40720

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

7.1
CVE-2026-35066

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg

7.1
CVE-2026-48997

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the

7.1
CVE-2026-48759

TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro

7.1
CVE-2026-53915

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

7.1
CVE-2017-20264

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to exec

7.1
CVE-2017-20265

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

7.1
CVE-2026-56209

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c

7.1
CVE-2026-56210

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds

7.1
CVE-2026-56211

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v

7.1
CVE-2019-25749

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbit

7.1
CVE-2019-25757

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary

7.1
CVE-2019-25759

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arb

7.1
CVE-2019-25761

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute a

7.1
CVE-2026-49338

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso

7.1
CVE-2026-49339

gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6

7.1
CVE-2026-49295

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c

7.1
CVE-2026-49346

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started