Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 666/1152
6.5
CVE-2026-0516

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to

6.5
CVE-2026-71225

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat

6.5
CVE-2026-71260

ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho

6.5
CVE-2026-71273

OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w

6.5
CVE-2026-71282

ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol

6.5
CVE-2026-7456

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec

6.5
CVE-2026-16100

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error

6.5
CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing

6.5
CVE-2026-49331

A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for

6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica

6.5
CVE-2026-20288

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nb

6.5
CVE-2026-20294

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem

6.5
CVE-2026-7646

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u

6.5
CVE-2026-10128

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit

6.5
CVE-2026-70439

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr

6.5
CVE-2026-7657

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and inef

6.5
CVE-2026-63457

A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

6.5
CVE-2026-7658

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t

6.5
CVE-2026-66885

Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b

6.5
CVE-2026-70616

boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl

6.5
CVE-2026-14204

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all

6.5
CVE-2026-16065

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil

6.5
CVE-2026-16954

The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi

6.5
CVE-2026-64640

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti

6.5
CVE-2026-25403

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

6.5
CVE-2026-28146

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers

6.5
CVE-2026-28178

Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.

6.5
CVE-2026-61959

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

6.5
CVE-2026-66425

Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cust

6.5
CVE-2026-66451

Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.

6.5
CVE-2026-66452

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

6.5
CVE-2026-66686

Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.

6.5
CVE-2026-66688

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.

6.5
CVE-2026-66695

Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.

6.5
CVE-2026-66703

Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.

6.5
CVE-2026-18275

Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a

6.5
CVE-2026-19127

An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflo

6.5
CVE-2026-43630

llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p

6.5
CVE-2026-48075

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

6.5
CVE-2026-48076

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie

6.5
CVE-2026-48083

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

6.5
CVE-2026-64662

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont

6.5
CVE-2026-64663

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup

6.5
CVE-2026-70557

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of

6.5
CVE-2026-70633

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres

6.5
CVE-2026-11907

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This

6.5
CVE-2026-15359

The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow

6.5
CVE-2026-16039

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders,

6.5
CVE-2026-16265

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r

6.5
CVE-2026-49008

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started