Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 696/1152
6.4
CVE-2026-18435

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S

6.4
CVE-2026-67332

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing

6.4
CVE-2026-12231

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info

6.4
CVE-2026-6972

The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of th

6.4
CVE-2026-7441

The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute

6.4
CVE-2026-71311

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1

6.4
CVE-2026-18400

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store

6.4
CVE-2026-18967

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a

6.4
CVE-2026-5158

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored C

6.4
CVE-2026-5391

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute

6.4
CVE-2026-18501

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre

6.4
CVE-2026-45573

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

6.4
CVE-2026-12801

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid

6.4
CVE-2026-47361

In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission gu

6.4
CVE-2026-18988

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a

6.4
CVE-2026-72720

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse

6.4
CVE-2026-66760

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges

6.4
CVE-2026-16974

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site

6.4
CVE-2026-62708

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

6.4
CVE-2026-18702

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost

6.4
CVE-2026-18708

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus

6.4
CVE-2026-18709

An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit

6.4
CVE-2026-64927

A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio

6.4
CVE-2026-19050

The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca

6.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated us

6.4
CVE-2026-72787

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft na

6.4
CVE-2026-3639

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `pp

6.4
CVE-2026-15948

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.4
CVE-2026-17090

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site

6.4
CVE-2026-11780

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.4
CVE-2026-15066

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in a

6.4
CVE-2026-15726

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in

6.4
CVE-2026-15604

The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin

6.4
CVE-2026-15790

The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,

6.4
CVE-2026-16758

The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all

6.4
CVE-2026-16775

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros

6.4
CVE-2026-18402

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v

6.4
CVE-2026-2357

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcod

6.4
CVE-2026-75010

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modobo

6.4
CVE-2026-12520

The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7

6.4
CVE-2026-70712

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

6.4
CVE-2026-71090

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.4
CVE-2026-71119

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.4
CVE-2026-47699

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From

6.4
CVE-2026-15421

The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site

6.4
CVE-2026-15446

The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load A

6.4
CVE-2026-50720

The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output

6.4
CVE-2026-76255

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power"

6.4
CVE-2026-76323

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

6.4
CVE-2026-76327

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started