Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 442/454
7.1
CVE-2026-63177

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng

7.1
CVE-2026-68447

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint

7.1
CVE-2026-16294

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode

7.1
CVE-2026-73291

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'

7.1
CVE-2026-17248

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper ne

7.1
CVE-2026-16494

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u

7.1
CVE-2026-73331

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr

7.1
CVE-2026-73617

Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplie

7.1
CVE-2026-27535

Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.

7.1
CVE-2026-27536

Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.

7.1
CVE-2026-27539

Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.

7.1
CVE-2026-28003

Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.

7.1
CVE-2026-28004

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.

7.1
CVE-2026-28158

Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.

7.1
CVE-2026-28170

Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.

7.1
CVE-2026-28173

Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.

7.1
CVE-2026-28175

Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.

7.1
CVE-2026-28187

Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 vers

7.1
CVE-2026-61960

Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.

7.1
CVE-2026-61965

Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.

7.1
CVE-2026-61974

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.

7.1
CVE-2026-65580

Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.

7.1
CVE-2026-66426

Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.

7.1
CVE-2026-66429

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.

7.1
CVE-2026-66449

Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.

7.1
CVE-2026-66468

Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.

7.1
CVE-2026-66655

Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.

7.1
CVE-2026-66697

Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 vers

7.1
CVE-2026-66698

Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.

7.1
CVE-2026-66700

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

7.1
CVE-2026-12036

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial V

7.1
CVE-2026-28154

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - C

7.1
CVE-2026-53784

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intend

7.1
CVE-2026-53785

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the int

7.1
CVE-2026-53802

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the r

7.1
CVE-2026-63426

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow

7.1
CVE-2026-68453

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2pro

7.1
CVE-2026-58416

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

7.1
CVE-2026-58437

Repository Visibility Manipulation via Git Push Options

7.1
CVE-2026-73266

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exp

7.1
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to e

7.1
CVE-2026-16896

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a

7.1
CVE-2026-48099

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path

7.1
CVE-2026-59714

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any auth

7.1
CVE-2026-72629

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Acc

7.1
CVE-2026-72630

Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Flee

7.1
CVE-2026-72632

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet re

7.1
CVE-2026-72643

Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is

7.1
CVE-2026-72675

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat

7.1
CVE-2026-19483

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Stor

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started