Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 670/1152
6.5
CVE-2026-14663

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of

6.5
CVE-2026-27537

Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.

6.5
CVE-2026-27999

Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.

6.5
CVE-2026-28155

Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.

6.5
CVE-2026-28159

Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.

6.5
CVE-2026-28174

Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.

6.5
CVE-2026-28181

Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.

6.5
CVE-2026-28182

Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.

6.5
CVE-2026-61978

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

6.5
CVE-2026-66444

Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.

6.5
CVE-2026-66454

Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.

6.5
CVE-2026-66456

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

6.5
CVE-2026-66459

Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.

6.5
CVE-2026-66460

Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.

6.5
CVE-2026-66464

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

6.5
CVE-2026-66467

Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.

6.5
CVE-2026-66471

Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.

6.5
CVE-2026-66660

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.

6.5
CVE-2026-66687

Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.

6.5
CVE-2026-66693

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

6.5
CVE-2026-73340

Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.

6.5
CVE-2026-73357

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.

6.5
CVE-2026-53786

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve

6.5
CVE-2026-53788

rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow

6.5
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o

6.5
CVE-2026-53792

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma

6.5
CVE-2026-70457

rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use

6.5
CVE-2026-70462

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows

6.5
CVE-2026-73559

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet

6.5
CVE-2026-24059

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat

6.5
CVE-2026-42931

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

6.5
CVE-2026-58428

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

6.5
CVE-2026-58442

Repository migration SSRF via multi-answer DNS allow-list bypass

6.5
CVE-2026-12236

The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By

6.5
CVE-2026-73562

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.

6.5
CVE-2026-16692

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas

6.5
CVE-2026-16853

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

6.5
CVE-2026-49089

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72631

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC

6.5
CVE-2026-72636

Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces

6.5
CVE-2026-72638

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).

6.5
CVE-2026-72639

Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the

6.5
CVE-2026-72640

The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manage

6.5
CVE-2026-72645

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc

6.5
CVE-2026-72647

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads

6.5
CVE-2026-72648

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can

6.5
CVE-2026-72651

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72653

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72656

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started