Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 591/1152
6.8
CVE-2026-70982

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-70983

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-70990

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-71007

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-71008

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-71029

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.8
CVE-2026-71084

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that

6.8
CVE-2026-15253

The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting

6.8
CVE-2026-18202

The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising t

6.8
CVE-2026-50719

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table fr

6.8
CVE-2026-18681

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 i

6.8
CVE-2026-55088

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts

6.8
CVE-2026-18849

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker w

6.8
CVE-2026-76827

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper w

6.8
CVE-2026-76252

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user

6.8
CVE-2026-19615

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route

6.8
CVE-2026-19697

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables,

6.8
CVE-2026-74992

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users wi

6.8
CVE-2026-18267

Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically pres

6.8
CVE-2026-18269

Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulnerability allows phys

6.8
CVE-2026-18271

Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physica

6.8
CVE-2026-18272

Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attac

6.8
CVE-2026-61625

VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.

6.8
CVE-2026-14601

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in

6.8
CVE-2026-16959

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it in

6.8
CVE-2026-16260

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom

6.8
CVE-2026-19093

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow

6.8
CVE-2026-17033

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert

6.8
CVE-2026-5006

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may

6.8
CVE-2026-56706

Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (form

6.8
CVE-2026-13215

The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a

6.8
CVE-2026-55535

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open

6.8
CVE-2026-24167

NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator co

6.8
CVE-2026-24168

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative

6.8
CVE-2026-65086

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS com

6.8
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se

6.8
CVE-2026-19226

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputtin

6.8
CVE-2026-32639

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

6.8
CVE-2026-47837

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri

6.8
CVE-2026-78275

Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

6.8
CVE-2026-59272

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is expose

6.8
CVE-2026-81092

mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in serv

6.8
CVE-2026-81095

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServ

6.8
CVE-2026-81099

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/htt

6.8
CVE-2026-81100

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src

6.8
CVE-2026-81706

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,

6.8
CVE-2026-59311

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choos

6.8
CVE-2026-12513

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly saniti

6.8
CVE-2026-82255

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr

6.8
CVE-2026-82020

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started