Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 488/1152
7.5
CVE-2026-55552

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated r

7.5
CVE-2026-55584

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control

7.5
CVE-2026-75124

PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the w

7.5
CVE-2026-82268

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats

7.5
CVE-2026-82270

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lac

7.5
CVE-2026-82275

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file acc

7.5
CVE-2026-82288

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint

7.5
CVE-2026-17203

IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive informatio

7.5
CVE-2026-18899

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.

7.5
CVE-2026-77037

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort

7.5
CVE-2026-77078

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially c

7.5
CVE-2026-81517

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough r

7.5
CVE-2026-81518

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during

7.5
CVE-2026-81520

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session ope

7.5
CVE-2026-82333

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted

7.5
CVE-2026-55784

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores

7.5
CVE-2026-55841

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylo

7.5
CVE-2026-76586

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount

7.5
CVE-2026-77007

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation

7.5
CVE-2026-82453

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attacker

7.5
CVE-2026-82472

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication,

7.5
CVE-2026-75807

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and i

7.5
CVE-2026-82638

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers t

7.5
CVE-2026-82639

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that

7.5
CVE-2026-82644

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which pro

7.5
CVE-2026-82655

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php

7.5
CVE-2026-82657

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements

7.5
CVE-2026-56718

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web ser

7.4
CVE-2026-20844

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2026-20853

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService all

7.4
CVE-2025-59960

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Ne

7.4
CVE-2025-65117

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed O

7.4
CVE-2025-59870

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secr

7.4
CVE-2025-15032

Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof

7.4
CVE-2026-22816

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d

7.4
CVE-2026-22865

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d

7.4
CVE-2025-11043

An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio

7.4
CVE-2026-21932

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

7.4
CVE-2025-68133

EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's

7.4
CVE-2025-68134

EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors

7.4
CVE-2025-68136

EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates

7.4
CVE-2025-68141

EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes`

7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s

7.4
CVE-2026-0723

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 1

7.4
CVE-2025-69821

An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service

7.4
CVE-2025-69822

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive informati

7.4
CVE-2026-21521

Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose inf

7.4
CVE-2026-21524

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to dis

7.4
CVE-2026-24123

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to vers

7.4
CVE-2025-69419

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started