Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 60/436
6.5
CVE-2026-8683

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm

6.5
CVE-2026-20262 KEV

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r

6.5
CVE-2025-55642

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ

6.5
CVE-2026-39197

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv

6.5
CVE-2026-49953

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo

6.5
CVE-2026-50892

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth

6.5
CVE-2026-52718

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse

6.5
CVE-2025-69332

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

6.5
CVE-2026-34892

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

6.5
CVE-2026-39491

Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

6.5
CVE-2026-39515

Subscriber Broken Access Control in Motors < 1.4.107 versions.

6.5
CVE-2026-39525

Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.

6.5
CVE-2026-39540

Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

6.5
CVE-2026-39584

Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

6.5
CVE-2026-40743

Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

6.5
CVE-2026-40773

Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.

6.5
CVE-2026-40782

Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.

6.5
CVE-2026-40790

Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.

6.5
CVE-2026-40793

Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

6.5
CVE-2026-40794

Subscriber Broken Access Control in myCred <= 3.0.3 versions.

6.5
CVE-2026-40795

Subscriber Broken Access Control in Amelia <= 2.2 versions.

6.5
CVE-2026-40796

Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.

6.5
CVE-2026-41556

Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.

6.5
CVE-2026-42378

Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.

6.5
CVE-2026-42640

Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

6.5
CVE-2026-42656

Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.

6.5
CVE-2026-42659

Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.

6.5
CVE-2026-42660

Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.

6.5
CVE-2026-42662

Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.

6.5
CVE-2026-42663

Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.

6.5
CVE-2026-42688

Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.

6.5
CVE-2026-42743

Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.

6.5
CVE-2026-42752

Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.

6.5
CVE-2026-48870

Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.

6.5
CVE-2026-48878

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.

6.5
CVE-2026-48880

Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.

6.5
CVE-2026-48887

Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

6.5
CVE-2026-48965

Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

6.5
CVE-2026-49773

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

6.5
CVE-2026-49775

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

6.5
CVE-2026-9258

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

6.5
CVE-2026-9259

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

6.5
CVE-2026-9262

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

6.5
CVE-2026-5149

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi

6.5
CVE-2026-2381

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a

6.5
CVE-2026-40809

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro

6.5
CVE-2026-54190

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

6.5
CVE-2026-54197

Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

6.5
CVE-2026-12302

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef

6.5
CVE-2026-12309

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started