Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 590/1152
6.8
CVE-2026-65834

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet

6.8
CVE-2026-14833

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend

6.8
CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor

6.8
CVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization

6.8
CVE-2026-67311

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail

6.8
CVE-2026-14817

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer

6.8
CVE-2026-18654

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v

6.8
CVE-2026-66313

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

6.8
CVE-2026-14872

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e

6.8
CVE-2026-14939

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi

6.8
CVE-2026-16069

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t

6.8
CVE-2026-16293

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po

6.8
CVE-2026-70620

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke

6.8
CVE-2026-55747

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir

6.8
CVE-2026-39924

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess

6.8
CVE-2026-64993

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo

6.8
CVE-2024-6541

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy

6.8
CVE-2026-5336

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren

6.8
CVE-2026-19017

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe

6.8
CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur

6.8
CVE-2026-15047

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside

6.8
CVE-2026-57279

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may

6.8
CVE-2026-19278

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu

6.8
CVE-2026-57262

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded

6.8
CVE-2026-57263

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec

6.8
CVE-2026-18636

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr

6.8
CVE-2026-62699

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to

6.8
CVE-2026-62702

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

6.8
CVE-2026-49349

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert

6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb

6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l

6.8
CVE-2026-17268

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

6.8
CVE-2026-17616

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

6.8
CVE-2026-73419

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth

6.8
CVE-2026-71194

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT

6.8
CVE-2026-73611

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configure

6.8
CVE-2026-58440

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of pr

6.8
CVE-2026-72666

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against El

6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputti

6.8
CVE-2026-72835

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated u

6.8
CVE-2026-73847

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant exec

6.8
CVE-2026-74984

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund

6.8
CVE-2026-50576

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

6.8
CVE-2026-60865

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp

6.8
CVE-2026-60895

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

6.8
CVE-2026-61308

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

6.8
CVE-2026-70751

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

6.8
CVE-2026-70780

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

6.8
CVE-2026-70843

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.8
CVE-2026-70972

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started