Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 665/1152
6.5
CVE-2026-69245

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of

6.5
CVE-2026-66312

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

6.5
CVE-2026-66314

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to

6.5
CVE-2026-66326

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.5
CVE-2026-8508

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug

6.5
CVE-2026-14816

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th

6.5
CVE-2026-16548

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be

6.5
CVE-2026-14194

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor

6.5
CVE-2026-14465

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human

6.5
CVE-2026-18772

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data

6.5
CVE-2026-18809

Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153

6.5
CVE-2026-63248

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an

6.5
CVE-2026-70368

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m

6.5
CVE-2026-67199

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop

6.5
CVE-2026-67618

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat

6.5
CVE-2026-24077

Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel

6.5
CVE-2026-24078

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

6.5
CVE-2026-47620

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing

6.5
CVE-2026-47621

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing

6.5
CVE-2026-69702

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a

6.5
CVE-2026-69704

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan

6.5
CVE-2026-70489

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio

6.5
CVE-2026-70491

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap

6.5
CVE-2026-70493

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built

6.5
CVE-2026-11421

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje

6.5
CVE-2026-15941

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f

6.5
CVE-2026-7753

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing

6.5
CVE-2026-16968

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users

6.5
CVE-2026-49004

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi

6.5
CVE-2026-66275

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-66276

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-66277

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-67553

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-67554

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-67555

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-67591

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-68077

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-68078

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-68080

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta

6.5
CVE-2026-11454

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object

6.5
CVE-2026-11977

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to

6.5
CVE-2026-15281

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w

6.5
CVE-2026-71205

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP

6.5
CVE-2026-71208

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl

6.5
CVE-2026-7726

The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on

6.5
CVE-2026-14574

In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec

6.5
CVE-2026-71244

Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r

6.5
CVE-2026-71247

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t

6.5
CVE-2026-71251

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started