Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 468/1152
7.5
CVE-2026-17948

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic

7.5
CVE-2026-17952

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to i

7.5
CVE-2026-17979

Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox

7.5
CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ

7.5
CVE-2026-12500

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a

7.5
CVE-2026-12687

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th

7.5
CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied

7.5
CVE-2026-15240

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper

7.5
CVE-2026-16529

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU proce

7.5
CVE-2026-44107

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f

7.5
CVE-2026-54365

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe

7.5
CVE-2026-54366

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack

7.5
CVE-2026-57859

e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a

7.5
CVE-2026-60074

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran

7.5
CVE-2026-60075

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi

7.5
CVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen

7.5
CVE-2026-12947

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive infor

7.5
CVE-2026-14519

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r

7.5
CVE-2026-16308

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remo

7.5
CVE-2026-41186

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components

7.5
CVE-2026-67349

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm

7.5
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR

7.5
CVE-2026-10842

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T

7.5
CVE-2026-28811

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver

7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s

7.5
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the

7.5
CVE-2026-62663

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt

7.5
CVE-2026-9322

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a

7.5
CVE-2024-25039

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1

7.5
CVE-2026-10545

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect

7.5
CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

7.5
CVE-2026-12942

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c

7.5
CVE-2026-15977

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf

7.5
CVE-2026-15978

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end

7.5
CVE-2026-18140

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy

7.5
CVE-2026-61536

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J

7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.

7.5
CVE-2026-68500

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli

7.5
CVE-2026-18064

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s

7.5
CVE-2026-63559

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r

7.5
CVE-2026-66360

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis

7.5
CVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up

7.5
CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc

7.5
CVE-2026-43829

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-43831

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-43832

Full details and mitigation steps are currently restricted and will be published at a later date.

7.5
CVE-2026-56671

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ

7.5
CVE-2026-56673

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path

7.5
CVE-2026-63222

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us

7.5
CVE-2026-12720

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started