Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 655/1152
6.5
CVE-2026-49799

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att

6.5
CVE-2026-54108

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing o

6.5
CVE-2026-55003

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-57976

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ

6.5
CVE-2026-57979

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

6.5
CVE-2026-59888

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From

6.5
CVE-2026-50366

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ

6.5
CVE-2026-50376

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50445

Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50468

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-50497

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo

6.5
CVE-2026-50504

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-54116

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in

6.5
CVE-2026-54126

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-55051

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information

6.5
CVE-2026-55054

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

6.5
CVE-2026-57982

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-58533

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58535

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58539

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58546

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-45070

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

6.5
CVE-2026-15714

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m

6.5
CVE-2026-47481

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t

6.5
CVE-2026-50659

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

6.5
CVE-2026-15766

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensi

6.5
CVE-2026-15768

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to

6.5
CVE-2026-15770

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensiti

6.5
CVE-2026-15775

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same ori

6.5
CVE-2026-15778

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attac

6.5
CVE-2026-48816

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv

6.5
CVE-2026-59889

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From

6.5
CVE-2026-46627

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m

6.5
CVE-2026-46629

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins

6.5
CVE-2026-46639

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g

6.5
CVE-2026-47732

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a

6.5
CVE-2026-36035

Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser

6.5
CVE-2026-13230

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan

6.5
CVE-2026-59259

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling

6.5
CVE-2026-61440

PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members

6.5
CVE-2026-61449

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in

6.5
CVE-2026-58559

DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit

6.5
CVE-2026-52865

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per

6.5
CVE-2026-54562

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow acc

6.5
CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist wh

6.5
CVE-2025-32781

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

6.5
CVE-2026-15746

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started