Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 560/1152
7.1
CVE-2026-53858

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY c

7.1
CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate

7.1
CVE-2026-53865

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-der

7.1
CVE-2026-46914

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a

7.1
CVE-2026-46932

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operatio

7.1
CVE-2024-49269

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

7.1
CVE-2025-31013

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow

7.1
CVE-2025-59560

Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.

7.1
CVE-2025-69104

Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.

7.1
CVE-2025-69151

Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions.

7.1
CVE-2026-22328

Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.

7.1
CVE-2026-22329

Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions.

7.1
CVE-2026-22339

Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.

7.1
CVE-2026-39548

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

7.1
CVE-2026-39597

Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.

7.1
CVE-2026-40765

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

7.1
CVE-2026-41557

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

7.1
CVE-2026-42385

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

7.1
CVE-2026-48869

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

7.1
CVE-2026-49074

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.

7.1
CVE-2026-49778

Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

7.1
CVE-2026-54188

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

7.1
CVE-2026-54189

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

7.1
CVE-2026-54192

Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

7.1
CVE-2026-54195

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

7.1
CVE-2026-8089

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin

7.1
CVE-2026-9570

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline

7.1
CVE-2025-68524

Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

7.1
CVE-2025-69140

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

7.1
CVE-2026-10641

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont

7.1
CVE-2026-40720

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

7.1
CVE-2026-35066

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg

7.1
CVE-2026-48997

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the

7.1
CVE-2026-48759

TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro

7.1
CVE-2026-53915

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

7.1
CVE-2017-20264

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to exec

7.1
CVE-2017-20265

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

7.1
CVE-2026-56209

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c

7.1
CVE-2026-56210

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds

7.1
CVE-2026-56211

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v

7.1
CVE-2019-25749

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbit

7.1
CVE-2019-25757

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary

7.1
CVE-2019-25759

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arb

7.1
CVE-2019-25761

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute a

7.1
CVE-2026-49338

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso

7.1
CVE-2026-49339

gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6

7.1
CVE-2026-49295

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c

7.1
CVE-2026-49346

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi

7.1
CVE-2026-4259

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp

7.1
CVE-2026-6858

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started