Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 571/1152
7.1
CVE-2026-16294

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode

7.1
CVE-2026-73291

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'

7.1
CVE-2026-17248

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper ne

7.1
CVE-2026-16494

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u

7.1
CVE-2026-73331

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr

7.1
CVE-2026-73617

Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplie

7.1
CVE-2026-27535

Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.

7.1
CVE-2026-27536

Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.

7.1
CVE-2026-27539

Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.

7.1
CVE-2026-28003

Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.

7.1
CVE-2026-28004

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.

7.1
CVE-2026-28158

Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.

7.1
CVE-2026-28170

Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.

7.1
CVE-2026-28173

Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.

7.1
CVE-2026-28175

Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.

7.1
CVE-2026-28187

Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 vers

7.1
CVE-2026-61960

Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.

7.1
CVE-2026-61965

Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.

7.1
CVE-2026-61974

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.

7.1
CVE-2026-65580

Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.

7.1
CVE-2026-66426

Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.

7.1
CVE-2026-66429

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.

7.1
CVE-2026-66449

Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.

7.1
CVE-2026-66468

Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.

7.1
CVE-2026-66655

Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.

7.1
CVE-2026-66697

Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 vers

7.1
CVE-2026-66698

Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.

7.1
CVE-2026-66700

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

7.1
CVE-2026-12036

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial V

7.1
CVE-2026-28154

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - C

7.1
CVE-2026-53784

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intend

7.1
CVE-2026-53785

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the int

7.1
CVE-2026-53802

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the r

7.1
CVE-2026-63426

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow

7.1
CVE-2026-68453

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2pro

7.1
CVE-2026-58416

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

7.1
CVE-2026-58437

Repository Visibility Manipulation via Git Push Options

7.1
CVE-2026-73266

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exp

7.1
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to e

7.1
CVE-2026-16896

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a

7.1
CVE-2026-48099

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path

7.1
CVE-2026-59714

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any auth

7.1
CVE-2026-72629

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Acc

7.1
CVE-2026-72630

Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Flee

7.1
CVE-2026-72632

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet re

7.1
CVE-2026-72643

Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is

7.1
CVE-2026-72675

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat

7.1
CVE-2026-19483

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Stor

7.1
CVE-2026-19680

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from th

7.1
CVE-2025-7639

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started