Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 440/454
7.1
CVE-2026-17744

Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to

7.1
CVE-2026-17750

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandb

7.1
CVE-2026-17811

Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perf

7.1
CVE-2026-17867

Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to

7.1
CVE-2026-17888

Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to

7.1
CVE-2026-14239

The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro

7.1
CVE-2026-44097

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fi

7.1
CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug

7.1
CVE-2026-55502

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r

7.1
CVE-2026-65981

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenti

7.1
CVE-2026-13725

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user

7.1
CVE-2025-71403

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute

7.1
CVE-2026-67329

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization b

7.1
CVE-2025-71400

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet

7.1
CVE-2026-9856

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi

7.1
CVE-2026-65875

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens

7.1
CVE-2026-66322

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

7.1
CVE-2026-18806

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im

7.1
CVE-2026-11368

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann

7.1
CVE-2026-70485

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebU

7.1
CVE-2026-64576

In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate

7.1
CVE-2026-71211

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr

7.1
CVE-2026-71276

Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor

7.1
CVE-2026-70448

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks

7.1
CVE-2026-9081

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerabil

7.1
CVE-2026-9130

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a

7.1
CVE-2026-28082

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

7.1
CVE-2026-28141

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

7.1
CVE-2026-28143

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

7.1
CVE-2026-28172

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

7.1
CVE-2026-28177

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

7.1
CVE-2026-61961

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

7.1
CVE-2026-61963

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.

7.1
CVE-2026-61964

Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.

7.1
CVE-2026-61982

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

7.1
CVE-2026-65509

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.

7.1
CVE-2026-65513

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.

7.1
CVE-2026-65515

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.

7.1
CVE-2026-65517

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

7.1
CVE-2026-65544

Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.

7.1
CVE-2026-65545

Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.

7.1
CVE-2026-65554

Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.

7.1
CVE-2026-65560

Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.

7.1
CVE-2026-65565

Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.

7.1
CVE-2026-66439

Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.

7.1
CVE-2026-66440

Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.

7.1
CVE-2026-66457

Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.

7.1
CVE-2026-66470

Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.

7.1
CVE-2026-66663

Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

7.1
CVE-2026-66664

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started