Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 575/1152
7.1
CVE-2026-68564

Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.

7.1
CVE-2026-74019

Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

7.1
CVE-2026-16925

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improp

7.1
CVE-2026-54616

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6

7.1
CVE-2026-54623

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

7.1
CVE-2026-16989

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper r

7.1
CVE-2026-46355

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinE

7.1
CVE-2026-55013

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locall

7.1
CVE-2026-49114

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_da

7.1
CVE-2026-62676

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shar

7.1
CVE-2026-30865

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)

7.1
CVE-2026-77219

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak he

7.1
CVE-2026-58003

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php

7.1
CVE-2026-63310

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu

7.1
CVE-2026-74584

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to u

7.1
CVE-2026-74603

In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM board

7.1
CVE-2026-74684

In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio net he

7.1
CVE-2026-74689

In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_setsock

7.1
CVE-2026-74703

In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts Whe

7.1
CVE-2026-74713

In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range vho

7.1
CVE-2026-77115

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without

7.1
CVE-2026-78203

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers t

7.1
CVE-2026-28162

Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

7.1
CVE-2026-28166

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

7.1
CVE-2026-28190

Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

7.1
CVE-2026-32476

Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

7.1
CVE-2026-66584

Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

7.1
CVE-2026-66599

Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.

7.1
CVE-2026-66610

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

7.1
CVE-2026-66623

Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.

7.1
CVE-2026-19685

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn

7.1
CVE-2026-71505

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou

7.1
CVE-2026-75369

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT

7.1
CVE-2026-32556

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

7.1
CVE-2026-78263

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

7.1
CVE-2026-78264

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

7.1
CVE-2026-78282

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

7.1
CVE-2026-55527

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized u

7.1
CVE-2026-55537

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webh

7.1
CVE-2026-55540

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() ra

7.1
CVE-2026-59184

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59186

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59187

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59189

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59982

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-55609

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear

7.1
CVE-2026-79786

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI wit

7.1
CVE-2026-79788

In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `de

7.1
CVE-2026-59981

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

7.1
CVE-2026-68513

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started