Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 436/436
4.0
CVE-2026-45536

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina

4.0
CVE-2026-56357

n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to

4.0
CVE-2026-57053

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandl

4.0
CVE-2026-53945

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques

4.0
CVE-2026-55688

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT

4.0
CVE-2026-13199

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul

4.0
CVE-2026-56360

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger

4.0
CVE-2026-14902

An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users

4.0
CVE-2026-58549

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af

4.0
CVE-2026-58550

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af

4.0
CVE-2026-58553

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af

4.0
CVE-2026-47085

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk

4.0
CVE-2026-16266

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in

4.0
CVE-2026-65069

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_

4.0
CVE-2026-18018

Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p

4.0
CVE-2026-56569

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config

4.0
CVE-2026-70595

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s

4.0
CVE-2024-10302

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo

4.0
CVE-2026-71381

Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could r

4.0
CVE-2026-71390

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur

4.0
CVE-2026-58560

Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affe

4.0
CVE-2026-58561

Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affe

4.0
CVE-2026-50126

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteo

4.0
CVE-2026-62584

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

4.0
CVE-2026-70719

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

4.0
CVE-2026-70916

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.0
CVE-2026-70917

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.0
CVE-2026-76367

In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript i

4.0
CVE-2026-80213

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length

4.0
CVE-2026-81680

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started
Browse by year 2026