Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 643/1152
6.5
CVE-2026-42743

Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.

6.5
CVE-2026-42752

Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.

6.5
CVE-2026-48870

Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.

6.5
CVE-2026-48878

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.

6.5
CVE-2026-48880

Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.

6.5
CVE-2026-48887

Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

6.5
CVE-2026-48965

Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

6.5
CVE-2026-49773

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

6.5
CVE-2026-49775

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

6.5
CVE-2026-9258

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

6.5
CVE-2026-9259

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

6.5
CVE-2026-9262

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

6.5
CVE-2026-5149

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi

6.5
CVE-2026-2381

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a

6.5
CVE-2026-40809

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro

6.5
CVE-2026-54190

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

6.5
CVE-2026-54197

Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

6.5
CVE-2026-12302

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef

6.5
CVE-2026-12309

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

6.5
CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15

6.5
CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12,

6.5
CVE-2026-53899

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff

6.5
CVE-2026-53844

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a

6.5
CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t

6.5
CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison

6.5
CVE-2026-0127

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory

6.5
CVE-2026-0128

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead

6.5
CVE-2026-0136

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv

6.5
CVE-2026-0144

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This cou

6.5
CVE-2026-12105

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi

6.5
CVE-2026-35261

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

6.5
CVE-2026-46810

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported

6.5
CVE-2026-46869

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are

6.5
CVE-2026-46871

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is

6.5
CVE-2026-46979

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and

6.5
CVE-2024-35690

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded

6.5
CVE-2024-37210

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security

6.5
CVE-2025-69137

Subscriber Broken Access Control in Genemy <= 1.6.6 versions.

6.5
CVE-2026-12450

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten

6.5
CVE-2026-12461

Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot

6.5
CVE-2026-27410

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

6.5
CVE-2026-39433

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

6.5
CVE-2026-40724

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

6.5
CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do

6.5
CVE-2026-45436

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

6.5
CVE-2026-47277

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro

6.5
CVE-2026-47340

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access.

6.5
CVE-2026-49071

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

6.5
CVE-2026-49072

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

6.5
CVE-2026-52716

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started