Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 667/1152
6.5
CVE-2026-56794

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo

6.5
CVE-2026-16637

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis

6.5
CVE-2026-48093

The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex

6.5
CVE-2026-44964

In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with

6.5
CVE-2026-47364

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado

6.5
CVE-2026-56818

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis

6.5
CVE-2026-70561

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,

6.5
CVE-2026-47127

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR

6.5
CVE-2026-16562

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics

6.5
CVE-2026-16590

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti

6.5
CVE-2026-16595

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti

6.5
CVE-2026-16992

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it

6.5
CVE-2026-18037

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it

6.5
CVE-2026-18465

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a

6.5
CVE-2026-18603

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or

6.5
CVE-2026-19345

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up

6.5
CVE-2026-19077

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d

6.5
CVE-2026-21061

Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM relate

6.5
CVE-2026-21078

Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows ad

6.5
CVE-2026-21079

Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr

6.5
CVE-2026-21080

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access

6.5
CVE-2026-21083

Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

6.5
CVE-2026-66404

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi

6.5
CVE-2026-19404

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati

6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,

6.5
CVE-2026-6373

Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow

6.5
CVE-2026-72726

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u

6.5
CVE-2026-70622

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t

6.5
CVE-2026-72739

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs

6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team

6.5
CVE-2026-71964

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t

6.5
CVE-2026-69114

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b

6.5
CVE-2026-72873

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/

6.5
CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex

6.5
CVE-2026-72907

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function

6.5
CVE-2026-72908

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template

6.5
CVE-2026-73033

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi

6.5
CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci

6.5
CVE-2026-24330

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali

6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

6.5
CVE-2026-19391

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the

6.5
CVE-2026-19517

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit

6.5
CVE-2026-19518

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu

6.5
CVE-2026-72539

An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem

6.5
CVE-2026-72541

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe

6.5
CVE-2026-72554

A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer

6.5
CVE-2026-72560

A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI

6.5
CVE-2026-72597

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started