Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 672/1152
6.5
CVE-2026-75047

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

6.5
CVE-2026-75049

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other

6.5
CVE-2026-68517

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outpu

6.5
CVE-2026-59903

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.

6.5
CVE-2026-73424

Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/int

6.5
CVE-2026-63667

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/

6.5
CVE-2026-63669

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation f

6.5
CVE-2026-75012

A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the func

6.5
CVE-2026-75013

A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the fi

6.5
CVE-2026-40506

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GE

6.5
CVE-2026-65976

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send r

6.5
CVE-2026-73560

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in

6.5
CVE-2026-75480

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls,

6.5
CVE-2026-10080

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field ty

6.5
CVE-2026-43667

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.1

6.5
CVE-2026-63178

Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group

6.5
CVE-2026-64715

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10

6.5
CVE-2026-64778

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS

6.5
CVE-2026-64787

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 a

6.5
CVE-2026-65330

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe

6.5
CVE-2026-65347

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. P

6.5
CVE-2026-69146

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.

6.5
CVE-2026-9859

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles o

6.5
CVE-2026-74945

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

6.5
CVE-2026-74948

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef

6.5
CVE-2026-74951

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

6.5
CVE-2026-74976

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140

6.5
CVE-2026-74980

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

6.5
CVE-2026-59949

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate t

6.5
CVE-2026-66636

Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.

6.5
CVE-2026-66637

Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.

6.5
CVE-2026-66638

Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.

6.5
CVE-2026-66639

Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.

6.5
CVE-2026-66640

Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.

6.5
CVE-2026-66641

Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.

6.5
CVE-2026-66643

Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.

6.5
CVE-2026-66644

Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.

6.5
CVE-2026-66645

Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.

6.5
CVE-2026-66646

Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.

6.5
CVE-2026-66651

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.

6.5
CVE-2026-66679

Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.

6.5
CVE-2026-68565

Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.

6.5
CVE-2026-73348

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

6.5
CVE-2026-73352

Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

6.5
CVE-2026-73359

Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

6.5
CVE-2026-73379

Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

6.5
CVE-2026-73395

Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi

6.5
CVE-2026-73398

Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

6.5
CVE-2026-73399

Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

6.5
CVE-2026-73404

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started