Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 447/454
7.1
CVE-2026-59981

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

7.1
CVE-2026-68513

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-68515

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-78892

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to

7.1
CVE-2026-80346

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type

7.1
CVE-2026-80350

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms

7.1
CVE-2026-80523

In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: k3: set hdma clock as critical HDMA

7.1
CVE-2026-80530

In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue

7.1
CVE-2026-80538

In the Linux kernel, the following vulnerability has been resolved: xfs: propagate errors from xfs_rtginode_load xfs_r

7.1
CVE-2026-80555

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fails

7.1
CVE-2026-80426

FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/s

7.1
CVE-2026-77611

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal

7.1
CVE-2026-47849

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Pa

7.1
CVE-2026-78261

Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

7.1
CVE-2026-78281

Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

7.1
CVE-2026-78283

Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

7.1
CVE-2026-78289

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

7.1
CVE-2026-78293

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

7.1
CVE-2026-81727

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa

7.1
CVE-2026-81529

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C

7.1
CVE-2026-81838

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 thr

7.1
CVE-2026-54085

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

7.1
CVE-2026-38821

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on th

7.1
CVE-2026-80662

In the Linux kernel, the following vulnerability has been resolved: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability

7.1
CVE-2026-80663

In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden daemon p

7.1
CVE-2026-80665

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if kvm_translate_vncr()

7.1
CVE-2026-80675

In the Linux kernel, the following vulnerability has been resolved: libbpf: Reject non-exclusive metadata maps in the s

7.1
CVE-2026-80685

In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folios in

7.1
CVE-2026-82241

Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.

7.1
CVE-2026-82246

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fai

7.1
CVE-2026-81760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi

7.1
CVE-2026-55066

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v

7.1
CVE-2026-82280

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt

7.1
CVE-2026-81533

An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL state

7.1
CVE-2026-82455

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-exi

7.1
CVE-2026-82648

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails

7.0
CVE-2025-20779

In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege

7.0
CVE-2025-20801

In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile

7.0
CVE-2026-20808

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Objec

7.0
CVE-2026-20814

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

7.0
CVE-2026-20815

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

7.0
CVE-2026-20830

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

7.0
CVE-2026-20836

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

7.0
CVE-2026-20842

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-20863

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-20869

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Man

7.0
CVE-2026-20943

Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

7.0
CVE-2026-21219

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2026-21221

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

7.0
CVE-2026-21939

Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started