Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 484/1152
7.5
CVE-2026-27462

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/inval

7.5
CVE-2026-27490

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being

7.5
CVE-2026-30866

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensit

7.5
CVE-2026-63421

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core

7.5
CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in o

7.5
CVE-2026-77781

Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS a

7.5
CVE-2026-59256

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens witho

7.5
CVE-2026-62243

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable

7.5
CVE-2026-62380

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain nul

7.5
CVE-2026-2996

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Valida

7.5
CVE-2026-62384

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read

7.5
CVE-2026-62388

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa

7.5
CVE-2026-63312

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E

7.5
CVE-2026-66393

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at

7.5
CVE-2026-74598

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validatio

7.5
CVE-2026-74621

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix sk_buff leak when the header

7.5
CVE-2026-74624

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: defer invalid log until af

7.5
CVE-2026-74625

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: release template ct on non-IP pa

7.5
CVE-2026-74626

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocat

7.5
CVE-2026-74678

In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: fix skb leak in ax88179_tx_

7.5
CVE-2026-74692

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() a

7.5
CVE-2026-74695

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst bef

7.5
CVE-2026-74696

In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport m

7.5
CVE-2026-74717

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error T

7.5
CVE-2026-47895

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no

7.5
CVE-2026-4671

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkificatio

7.5
CVE-2026-9769

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During Ju

7.5
CVE-2026-78206

exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, tot

7.5
CVE-2026-78208

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate

7.5
CVE-2026-78212

4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remot

7.5
CVE-2026-75899

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parse

7.5
CVE-2026-75931

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit

7.5
CVE-2026-75975

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6

7.5
CVE-2026-76172

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never

7.5
CVE-2026-28153

Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS,

7.5
CVE-2026-28167

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

7.5
CVE-2026-66585

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

7.5
CVE-2026-76848

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validati

7.5
CVE-2025-68825

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta

7.5
CVE-2026-21752

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or

7.5
CVE-2026-66907

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

7.5
CVE-2026-66908

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:

7.5
CVE-2026-71922

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cg

7.5
CVE-2026-75371

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-

7.5
CVE-2026-75368

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause

7.5
CVE-2026-76098

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS throu

7.5
CVE-2026-77384

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh pa

7.5
CVE-2026-78268

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Tel

7.5
CVE-2026-66766

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vu

7.5
CVE-2026-56709

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started