Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 668/1152
6.5
CVE-2026-72598

A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se

6.5
CVE-2026-72604

A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar

6.5
CVE-2026-72608

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

6.5
CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when

6.5
CVE-2026-72780

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey

6.5
CVE-2026-72782

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre

6.5
CVE-2026-18638

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces

6.5
CVE-2026-53414

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic

6.5
CVE-2026-20747

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni

6.5
CVE-2026-40375

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-47285

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau

6.5
CVE-2026-48375

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service

6.5
CVE-2026-48436

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur

6.5
CVE-2026-58639

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over

6.5
CVE-2026-59138

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo

6.5
CVE-2026-61345

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo

6.5
CVE-2026-61918

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-61921

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-61924

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-62714

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62715

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62716

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62718

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62720

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62742

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62745

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62750

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad

6.5
CVE-2026-62782

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-62814

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62837

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw

6.5
CVE-2026-62839

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov

6.5
CVE-2026-62902

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information

6.5
CVE-2026-62912

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw

6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net

6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network

6.5
CVE-2026-63516

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over

6.5
CVE-2026-65769

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to

6.5
CVE-2026-65785

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen

6.5
CVE-2026-65794

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-65806

Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-65813

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over

6.5
CVE-2026-66301

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized

6.5
CVE-2026-70327

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-70328

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-48411

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

6.5
CVE-2026-72712

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash

6.5
CVE-2026-73216

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr

6.5
CVE-2026-18695

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could

6.5
CVE-2026-18696

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to

6.5
CVE-2026-18699

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started