Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 596/1152
6.7
CVE-2026-60776

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader

6.7
CVE-2026-60846

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server

6.7
CVE-2026-61043

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).

6.7
CVE-2026-61176

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

6.7
CVE-2026-61182

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Da

6.7
CVE-2026-62503

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

6.7
CVE-2026-46737

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the

6.7
CVE-2026-27377

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

6.7
CVE-2026-66028

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe

6.7
CVE-2026-20486

In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation

6.7
CVE-2026-9593

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the

6.7
CVE-2026-24076

Memory Corruption when processing registry values with incorrect types using a direct query method.

6.7
CVE-2026-48121

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto

6.7
CVE-2026-70594

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions

6.7
CVE-2026-66344

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi

6.7
CVE-2026-66839

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil

6.7
CVE-2026-16742

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed

6.7
CVE-2026-72719

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf

6.7
CVE-2026-71968

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo

6.7
CVE-2026-71969

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a

6.7
CVE-2026-62769

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-62881

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-62883

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65795

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65797

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65798

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65799

Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-70304

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-70330

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65680

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el

6.7
CVE-2026-66016

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessi

6.7
CVE-2026-46380

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSF

6.7
CVE-2026-44845

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an a

6.7
CVE-2026-71477

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/

6.7
CVE-2025-9211

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 al

6.7
CVE-2026-61313

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

6.7
CVE-2026-70698

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

6.7
CVE-2026-71109

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.7
CVE-2026-76228

Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injec

6.7
CVE-2026-76229

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize man

6.7
CVE-2026-76230

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-pr

6.7
CVE-2026-76231

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where use

6.7
CVE-2026-76232

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the

6.7
CVE-2026-76233

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the d

6.7
CVE-2026-19321

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerab

6.7
CVE-2026-16914

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bo

6.7
CVE-2026-76322

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could cr

6.7
CVE-2026-76328

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

6.7
CVE-2026-16944

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-base

6.7
CVE-2026-16951

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due t

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started