Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 54/91
CVE-2026-54217

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send

CVE-2026-54218

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally

CVE-2026-48094

The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse

CVE-2026-66494

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut

CVE-2026-15570

An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245

CVE-2026-66914

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated

CVE-2026-62992

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio

CVE-2026-62996

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From

CVE-2026-66059

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose

CVE-2026-14644

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with

CVE-2026-17593

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi

CVE-2026-17594

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th

CVE-2026-17595

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select

CVE-2026-17596

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre

CVE-2026-17597

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f

CVE-2026-17598

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when

CVE-2026-17599

Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th

CVE-2026-17600

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio

CVE-2026-17601

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their

CVE-2026-17603

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data

CVE-2026-67585

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent

CVE-2026-64638

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici

CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo

CVE-2026-66000

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation

CVE-2026-69127

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl

CVE-2026-71847

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume

CVE-2026-71852

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and larg

CVE-2026-47659

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47660

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47661

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-48007

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to

CVE-2026-71870

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti

CVE-2026-46358

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi

CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47663

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47664

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-9030

A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han

CVE-2026-9031

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da

CVE-2026-45808

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide

CVE-2026-47243

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th

CVE-2026-58262

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou

CVE-2026-48047

XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to

CVE-2026-48122

Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP

CVE-2026-8798

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried

CVE-2026-13505

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser

CVE-2026-68081

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fail

CVE-2026-71502

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template

CVE-2026-70395

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f

CVE-2026-13133

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is lo

CVE-2026-21074

Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands wi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started