Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 61/436
6.5
CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15

6.5
CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12,

6.5
CVE-2026-53899

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff

6.5
CVE-2026-53844

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a

6.5
CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t

6.5
CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison

6.5
CVE-2026-0127

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory

6.5
CVE-2026-0128

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead

6.5
CVE-2026-0136

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv

6.5
CVE-2026-0144

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This cou

6.5
CVE-2026-12105

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi

6.5
CVE-2026-35261

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

6.5
CVE-2026-46810

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported

6.5
CVE-2026-46869

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are

6.5
CVE-2026-46871

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is

6.5
CVE-2026-46979

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and

6.5
CVE-2024-35690

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded

6.5
CVE-2024-37210

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security

6.5
CVE-2025-69137

Subscriber Broken Access Control in Genemy <= 1.6.6 versions.

6.5
CVE-2026-12450

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten

6.5
CVE-2026-12461

Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot

6.5
CVE-2026-27410

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

6.5
CVE-2026-39433

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

6.5
CVE-2026-40724

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

6.5
CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do

6.5
CVE-2026-45436

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

6.5
CVE-2026-47277

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro

6.5
CVE-2026-47340

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access.

6.5
CVE-2026-49071

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

6.5
CVE-2026-49072

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

6.5
CVE-2026-52716

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

6.5
CVE-2026-54817

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover

6.5
CVE-2024-47477

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un

6.5
CVE-2026-2675

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th

6.5
CVE-2026-7300

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In

6.5
CVE-2026-55197

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut

6.5
CVE-2026-55198

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a

6.5
CVE-2026-32682

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or

6.5
CVE-2026-49133

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri

6.5
CVE-2026-12568

The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit

6.5
CVE-2026-44645

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,

6.5
CVE-2026-50201

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati

6.5
CVE-2026-9815

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti

6.5
CVE-2026-42490

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.5
CVE-2026-44942

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series

6.5
CVE-2025-58175

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2

6.5
CVE-2026-22551

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r

6.5
CVE-2026-56024

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue

6.5
CVE-2025-15661

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()

6.5
CVE-2026-45696

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started