Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 64/436
6.5
CVE-2026-55962

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl

6.5
CVE-2026-6329

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all

6.5
CVE-2026-6330

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i

6.5
CVE-2026-40084

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra

6.5
CVE-2026-40941

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign

6.5
CVE-2026-12993

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d

6.5
CVE-2026-9219

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive

6.5
CVE-2026-13226

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection

6.5
CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth

6.5
CVE-2026-8380

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post

6.5
CVE-2026-1869

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U

6.5
CVE-2026-57620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu

6.5
CVE-2026-57914

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow

6.5
CVE-2025-68074

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

6.5
CVE-2025-68075

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

6.5
CVE-2026-30040

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary

6.5
CVE-2026-4339

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against int

6.5
CVE-2026-52701

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

6.5
CVE-2026-56046

Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

6.5
CVE-2026-56048

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <=

6.5
CVE-2026-57313

Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

6.5
CVE-2026-57316

Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

6.5
CVE-2026-57318

Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

6.5
CVE-2026-57324

Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

6.5
CVE-2026-57431

Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

6.5
CVE-2026-57617

Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

6.5
CVE-2026-57618

Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

6.5
CVE-2026-57629

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

6.5
CVE-2026-57635

Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versio

6.5
CVE-2026-57638

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

6.5
CVE-2026-57641

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

6.5
CVE-2026-57650

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

6.5
CVE-2026-57651

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

6.5
CVE-2026-57654

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

6.5
CVE-2026-9639

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticat

6.5
CVE-2026-47204

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9

6.5
CVE-2026-47207

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9

6.5
CVE-2026-44734

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v

6.5
CVE-2026-44735

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en

6.5
CVE-2026-44736

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint a

6.5
CVE-2026-53577

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution

6.5
CVE-2026-13331

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection

6.5
CVE-2026-13333

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection

6.5
CVE-2026-3462

The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks

6.5
CVE-2026-45259

sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation

6.5
CVE-2026-58051

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin

6.5
CVE-2026-58058

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li

6.5
CVE-2026-10593

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications.

6.5
CVE-2026-57328

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

6.5
CVE-2026-57329

Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started