Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 63/91
CVE-2026-67283

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenti

CVE-2026-67284

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authentica

CVE-2026-67285

Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u

CVE-2026-18171

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und

CVE-2026-67286

Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8

CVE-2026-67287

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated att

CVE-2026-73288

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crat

CVE-2026-73374

A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter

CVE-2026-73405

An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to S

CVE-2026-73431

Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac

CVE-2026-73432

Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization

CVE-2026-15803

In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin

CVE-2026-64639

Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (cu

CVE-2026-73297

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked

CVE-2026-73298

The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-dr

CVE-2026-18673

When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service

CVE-2026-18675

The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose ki

CVE-2026-18676

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the ope

CVE-2026-18677

In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's ku

CVE-2026-18678

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS

CVE-2026-18679

When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane co

CVE-2026-73307

Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts u

CVE-2026-73407

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/

CVE-2026-73409

Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builde

CVE-2026-73411

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/u

CVE-2026-73412

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on U

CVE-2026-73413

Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop i

CVE-2026-73414

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/w

CVE-2026-73415

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit

CVE-2026-73422

Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS ge

CVE-2026-73423

Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline install

CVE-2026-73427

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cro

CVE-2026-73491

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

CVE-2026-73492

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

CVE-2026-73499

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,

CVE-2026-73500

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,

CVE-2026-15141

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests con

CVE-2026-47718

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` s

CVE-2026-46382

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a

CVE-2026-46688

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an

CVE-2026-0289

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user

CVE-2026-0290

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables

CVE-2026-0291

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Li

CVE-2026-0292

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enabl

CVE-2026-0293

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privil

CVE-2026-0294

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS device

CVE-2026-0295

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged

CVE-2026-0296

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attac

CVE-2026-0297

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (Mi

CVE-2026-0298

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started