Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 642/1152
6.5
CVE-2026-50634

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was

6.5
CVE-2026-50082

The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att

6.5
CVE-2026-5792

Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market

6.5
CVE-2026-53982

Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker

6.5
CVE-2026-7184

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp

6.5
CVE-2026-42853

ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and

6.5
CVE-2026-44784

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be

6.5
CVE-2026-47124

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be

6.5
CVE-2026-53520

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to b

6.5
CVE-2026-53522

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be

6.5
CVE-2026-53824

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin

6.5
CVE-2026-53825

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows aut

6.5
CVE-2026-53827

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-con

6.5
CVE-2026-53830

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and

6.5
CVE-2026-53839

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host

6.5
CVE-2026-11442

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker

6.5
CVE-2025-64215

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co

6.5
CVE-2026-48969

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

6.5
CVE-2025-15659

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

6.5
CVE-2026-8683

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm

6.5
CVE-2026-20262 KEV

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r

6.5
CVE-2025-55642

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ

6.5
CVE-2026-39197

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv

6.5
CVE-2026-49953

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo

6.5
CVE-2026-50892

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth

6.5
CVE-2026-52718

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse

6.5
CVE-2025-69332

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

6.5
CVE-2026-34892

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

6.5
CVE-2026-39491

Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

6.5
CVE-2026-39515

Subscriber Broken Access Control in Motors < 1.4.107 versions.

6.5
CVE-2026-39525

Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.

6.5
CVE-2026-39540

Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

6.5
CVE-2026-39584

Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

6.5
CVE-2026-40743

Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

6.5
CVE-2026-40773

Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.

6.5
CVE-2026-40782

Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.

6.5
CVE-2026-40790

Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.

6.5
CVE-2026-40793

Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

6.5
CVE-2026-40794

Subscriber Broken Access Control in myCred <= 3.0.3 versions.

6.5
CVE-2026-40795

Subscriber Broken Access Control in Amelia <= 2.2 versions.

6.5
CVE-2026-40796

Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.

6.5
CVE-2026-41556

Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.

6.5
CVE-2026-42378

Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.

6.5
CVE-2026-42640

Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

6.5
CVE-2026-42656

Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.

6.5
CVE-2026-42659

Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.

6.5
CVE-2026-42660

Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.

6.5
CVE-2026-42662

Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.

6.5
CVE-2026-42663

Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.

6.5
CVE-2026-42688

Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started