Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 432/436
4.2
CVE-2026-55608

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior

4.2
CVE-2024-23572

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as

4.2
CVE-2024-23578

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS)

4.2
CVE-2026-21761

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may

4.2
CVE-2026-16212

A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/model

4.2
CVE-2026-47122

Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `

4.2
CVE-2026-12548

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw

4.2
CVE-2026-60709

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

4.2
CVE-2026-60760

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operatio

4.2
CVE-2026-61123

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

4.2
CVE-2026-62489

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

4.2
CVE-2026-13068

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac

4.2
CVE-2026-65699

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica

4.2
CVE-2026-14926

The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the

4.2
CVE-2026-4932

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica

4.2
CVE-2026-15157

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type he

4.2
CVE-2026-17659

Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had

4.2
CVE-2026-17724

Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scri

4.2
CVE-2026-17739

Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced

4.2
CVE-2026-17747

Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remo

4.2
CVE-2026-59328

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse

4.2
CVE-2026-16970

The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto

4.2
CVE-2026-10031

SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-direc

4.2
CVE-2026-18211

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo

4.2
CVE-2026-18218

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp

4.2
CVE-2026-67293

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability.

4.2
CVE-2026-70434

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to c

4.2
CVE-2026-70435

A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permissio

4.2
CVE-2026-41861

Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with

4.2
CVE-2026-15970

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypa

4.2
CVE-2026-19016

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission

4.2
CVE-2026-58241

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi

4.2
CVE-2026-20763

Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may all

4.2
CVE-2026-20765

Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allo

4.2
CVE-2026-18703

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe

4.2
CVE-2026-66376

Credentials for a deleted user may remain valid for a short period under specific conditions.

4.2
CVE-2026-7366

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower G

4.2
CVE-2026-14666

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query

4.2
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_

4.2
CVE-2026-19730

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TR

4.2
CVE-2026-73657

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4,

4.2
CVE-2026-12363

The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fra

4.2
CVE-2026-74247

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Se

4.2
CVE-2026-18165

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin val

4.2
CVE-2026-74867

SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authentication bra

4.2
CVE-2026-15754

Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate

4.2
CVE-2026-75833

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contai

4.2
CVE-2026-75850

ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP hand

4.2
CVE-2026-74973

Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.3

4.2
CVE-2026-70793

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started