Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 570/1152
7.1
CVE-2026-66702

Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.

7.1
CVE-2026-66705

Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.

7.1
CVE-2026-66707

Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

7.1
CVE-2026-66711

Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.

7.1
CVE-2026-18277

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remo

7.1
CVE-2026-5856

Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack

7.1
CVE-2026-70635

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica

7.1
CVE-2026-49746

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor

7.1
CVE-2026-18497

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p

7.1
CVE-2026-71556

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera

7.1
CVE-2025-71409

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages

7.1
CVE-2025-71412

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion

7.1
CVE-2026-66060

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co

7.1
CVE-2026-66061

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS

7.1
CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem

7.1
CVE-2026-21058

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with

7.1
CVE-2026-21059

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac

7.1
CVE-2026-68103

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell to a

7.1
CVE-2026-68172

In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned address

7.1
CVE-2026-68173

In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub->compl

7.1
CVE-2026-68229

In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list en

7.1
CVE-2026-68258

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type

7.1
CVE-2026-68262

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_set_u

7.1
CVE-2026-68293

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 d

7.1
CVE-2026-68348

In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string pa

7.1
CVE-2026-68402

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking

7.1
CVE-2026-68420

In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbound p

7.1
CVE-2026-68425

In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reasse

7.1
CVE-2026-72690

An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i

7.1
CVE-2026-72731

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l

7.1
CVE-2026-69112

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec

7.1
CVE-2026-18620

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab

7.1
CVE-2026-72910

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p

7.1
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low

7.1
CVE-2026-72546

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org

7.1
CVE-2026-72547

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org

7.1
CVE-2026-72607

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

7.1
CVE-2026-72609

An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wit

7.1
CVE-2026-18640

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm

7.1
CVE-2026-42142

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee

7.1
CVE-2026-48495

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS

7.1
CVE-2026-53416

Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca

7.1
CVE-2026-48442

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

7.1
CVE-2026-65675

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security

7.1
CVE-2026-18687

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para

7.1
CVE-2026-18688

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory

7.1
CVE-2026-18694

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus

7.1
CVE-2026-18711

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to

7.1
CVE-2026-63177

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng

7.1
CVE-2026-68447

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started