Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 433/454
7.1
CVE-2026-56051

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

7.1
CVE-2026-56071

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

7.1
CVE-2026-49839

jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval

7.1
CVE-2026-55700

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro

7.1
CVE-2026-57520

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi

7.1
CVE-2026-57918

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d

7.1
CVE-2026-56011

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

7.1
CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

7.1
CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

7.1
CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

7.1
CVE-2026-56043

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

7.1
CVE-2026-56044

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

7.1
CVE-2026-56045

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

7.1
CVE-2026-56047

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

7.1
CVE-2026-56072

Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

7.1
CVE-2026-57312

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

7.1
CVE-2026-57314

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

7.1
CVE-2026-57317

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

7.1
CVE-2026-57319

Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

7.1
CVE-2026-57321

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

7.1
CVE-2026-57322

Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

7.1
CVE-2026-57325

Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

7.1
CVE-2026-47214

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

7.1
CVE-2026-53303

In the Linux kernel, the following vulnerability has been resolved: f2fs: protect extension_list reading with sb_lock i

7.1
CVE-2026-33560

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a

7.1
CVE-2026-49413

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin

7.1
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl.

7.1
CVE-2026-57346

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy al

7.1
CVE-2026-40522

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au

7.1
CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(

7.1
CVE-2026-54371

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows

7.1
CVE-2026-57320

Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

7.1
CVE-2026-57332

Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

7.1
CVE-2026-57333

Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

7.1
CVE-2026-57336

Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.

7.1
CVE-2026-57337

Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.

7.1
CVE-2026-57338

Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.

7.1
CVE-2026-43701

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS

7.1
CVE-2026-43725

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.

7.1
CVE-2026-10546

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component (

7.1
CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulner

7.1
CVE-2026-56320

Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_i

7.1
CVE-2026-53904

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass

7.1
CVE-2026-53905

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree

7.1
CVE-2026-53330

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_e

7.1
CVE-2026-53346

In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFI

7.1
CVE-2026-55153

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool.

7.1
CVE-2025-69152

Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.

7.1
CVE-2025-69153

Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.

7.1
CVE-2025-69154

Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started