Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 6/436
6.8
CVE-2026-48117

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a

6.8
CVE-2026-55201

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function

6.8
CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut

6.8
CVE-2026-56109

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()

6.8
CVE-2026-7842

The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde

6.8
CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv

6.8
CVE-2026-52809

Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act

6.8
CVE-2026-53196

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_

6.8
CVE-2026-55411

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI

6.8
CVE-2026-50021

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh

6.8
CVE-2026-50573

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package

6.8
CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e

6.8
CVE-2026-9699

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before

6.8
CVE-2026-47775

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,

6.8
CVE-2025-7386

Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51

6.8
CVE-2026-13595

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an

6.8
CVE-2026-57948

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the

6.8
CVE-2026-14440

Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati

6.8
CVE-2026-10077

The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a

6.8
CVE-2026-58522

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

6.8
CVE-2026-58404

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t

6.8
CVE-2026-36027

An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via

6.8
CVE-2026-36028

A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass

6.8
CVE-2026-59804

Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat

6.8
CVE-2026-59807

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex

6.8
CVE-2026-58208

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.

6.8
CVE-2026-59208

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi

6.8
CVE-2026-55689

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skippe

6.8
CVE-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex

6.8
CVE-2026-55885

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download

6.8
CVE-2026-57216

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str

6.8
CVE-2026-49168

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi

6.8
CVE-2026-50298

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a phy

6.8
CVE-2026-50299

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a p

6.8
CVE-2026-54132

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attac

6.8
CVE-2026-50426

Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.

6.8
CVE-2026-50492

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with

6.8
CVE-2026-50668

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.

6.8
CVE-2026-58528

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat

6.8
CVE-2026-47996

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A

6.8
CVE-2026-24234

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-acces

6.8
CVE-2026-48338

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit

6.8
CVE-2026-48312

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur

6.8
CVE-2026-62843

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

6.8
CVE-2026-52888

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.

6.8
CVE-2026-46404

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res

6.8
CVE-2026-48009

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re

6.8
CVE-2026-12283

Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard

6.8
CVE-2026-54497

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4

6.8
CVE-2026-59776

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started