Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 441/454
7.1
CVE-2026-66690

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.

7.1
CVE-2026-66694

Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.

7.1
CVE-2026-66702

Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.

7.1
CVE-2026-66705

Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.

7.1
CVE-2026-66707

Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

7.1
CVE-2026-66711

Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.

7.1
CVE-2026-18277

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remo

7.1
CVE-2026-5856

Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack

7.1
CVE-2026-70635

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica

7.1
CVE-2026-49746

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor

7.1
CVE-2026-18497

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p

7.1
CVE-2026-71556

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera

7.1
CVE-2025-71409

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages

7.1
CVE-2025-71412

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion

7.1
CVE-2026-66060

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co

7.1
CVE-2026-66061

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS

7.1
CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem

7.1
CVE-2026-21058

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with

7.1
CVE-2026-21059

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac

7.1
CVE-2026-68103

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell to a

7.1
CVE-2026-68172

In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned address

7.1
CVE-2026-68173

In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub->compl

7.1
CVE-2026-68229

In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list en

7.1
CVE-2026-68258

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type

7.1
CVE-2026-68262

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_set_u

7.1
CVE-2026-68293

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 d

7.1
CVE-2026-68348

In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string pa

7.1
CVE-2026-68402

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking

7.1
CVE-2026-68420

In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbound p

7.1
CVE-2026-68425

In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reasse

7.1
CVE-2026-72690

An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i

7.1
CVE-2026-72731

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l

7.1
CVE-2026-69112

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec

7.1
CVE-2026-18620

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab

7.1
CVE-2026-72910

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p

7.1
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low

7.1
CVE-2026-72546

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org

7.1
CVE-2026-72547

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org

7.1
CVE-2026-72607

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

7.1
CVE-2026-72609

An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wit

7.1
CVE-2026-18640

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm

7.1
CVE-2026-42142

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee

7.1
CVE-2026-48495

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS

7.1
CVE-2026-53416

Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca

7.1
CVE-2026-48442

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

7.1
CVE-2026-65675

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security

7.1
CVE-2026-18687

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para

7.1
CVE-2026-18688

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory

7.1
CVE-2026-18694

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus

7.1
CVE-2026-18711

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started