Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 678/1152
6.5
CVE-2026-71054

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily

6.5
CVE-2026-74771

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab

6.5
CVE-2026-62326

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

6.5
CVE-2026-47860

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the c

6.5
CVE-2026-59274

The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an at

6.5
CVE-2026-59278

JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these m

6.5
CVE-2026-78273

Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.

6.5
CVE-2026-17562

Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu

6.5
CVE-2026-81658

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving

6.5
CVE-2026-40526

Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read a

6.5
CVE-2026-80210

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the

6.5
CVE-2026-81101

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i

6.5
CVE-2026-54732

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js u

6.5
CVE-2026-59317

DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and

6.5
CVE-2026-59320

When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing th

6.5
CVE-2026-81521

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv

6.5
CVE-2026-81526

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i

6.5
CVE-2026-81527

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver

6.5
CVE-2026-81729

Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs

6.5
CVE-2026-68967

Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that

6.5
CVE-2026-61802

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

6.5
CVE-2026-16759

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited

6.5
CVE-2026-82123

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & L

6.5
CVE-2026-9548

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain

6.5
CVE-2026-40014

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU dispr

6.5
CVE-2026-40017

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal ha

6.5
CVE-2026-52687

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression st

6.5
CVE-2026-73209

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its

6.5
CVE-2026-82250

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs w

6.5
CVE-2026-81341

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer

6.5
CVE-2026-55545

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce

6.5
CVE-2026-55549

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from

6.5
CVE-2026-66324

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoo

6.5
CVE-2026-77939

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack

6.5
CVE-2026-82265

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing una

6.5
CVE-2026-82271

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen

6.5
CVE-2026-82272

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset e

6.5
CVE-2026-82273

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when

6.5
CVE-2026-82306

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi

6.5
CVE-2026-13734

Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali

6.5
CVE-2026-55855

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

6.5
CVE-2026-18233

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints

6.5
CVE-2026-18234

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling be

6.5
CVE-2026-77008

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or

6.5
CVE-2026-77010

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation che

6.5
CVE-2026-82462

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali

6.5
CVE-2026-82634

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-

6.5
CVE-2026-82547

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks

6.5
CVE-2026-82643

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha

6.4
CVE-2025-14627

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started