Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 661/1152
6.5
CVE-2026-66337

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes

6.5
CVE-2026-66339

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t

6.5
CVE-2026-14955

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version

6.5
CVE-2026-10681

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre

6.5
CVE-2026-14568

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor

6.5
CVE-2026-66412

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston

6.5
CVE-2026-55970

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a

6.5
CVE-2026-10819

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number o

6.5
CVE-2026-59557

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

6.5
CVE-2026-59559

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 version

6.5
CVE-2026-59560

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

6.5
CVE-2026-65433

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

6.5
CVE-2026-65434

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

6.5
CVE-2026-65435

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

6.5
CVE-2026-65561

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

6.5
CVE-2026-65562

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

6.5
CVE-2026-66433

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

6.5
CVE-2026-66434

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

6.5
CVE-2026-66445

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

6.5
CVE-2026-66448

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

6.5
CVE-2026-66399

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi

6.5
CVE-2026-66391

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap

6.5
CVE-2026-64649

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr

6.5
CVE-2026-65618

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized

6.5
CVE-2026-65924

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (

6.5
CVE-2026-65925

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret

6.5
CVE-2026-66018

Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor

6.5
CVE-2026-43792

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.

6.5
CVE-2026-43804

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6

6.5
CVE-2026-43821

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPa

6.5
CVE-2026-64728

A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6

6.5
CVE-2026-64730

The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6

6.5
CVE-2026-64735

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 an

6.5
CVE-2026-64742

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 an

6.5
CVE-2026-64743

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.

6.5
CVE-2026-65445

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

6.5
CVE-2026-65448

Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

6.5
CVE-2026-6251

The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i

6.5
CVE-2026-15267

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL

6.5
CVE-2026-18047

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo

6.5
CVE-2026-62429

Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cl

6.5
CVE-2026-62435

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.5
CVE-2026-62436

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.5
CVE-2026-61487

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated

6.5
CVE-2026-66749

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th

6.5
CVE-2026-7868

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an

6.5
CVE-2026-15304

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions

6.5
CVE-2026-66063

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.

6.5
CVE-2026-63238

An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl

6.5
CVE-2026-18192

VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started