Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 7/436
6.8
CVE-2026-15927

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints

6.8
CVE-2026-47045

Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.

6.8
CVE-2026-60612

Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans).

6.8
CVE-2026-60666

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The

6.8
CVE-2026-60687

Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).

6.8
CVE-2026-60744

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Suppor

6.8
CVE-2026-60795

Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor

6.8
CVE-2026-60862

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

6.8
CVE-2026-61134

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th

6.8
CVE-2026-62559

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.8
CVE-2026-8988

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of th

6.8
CVE-2026-8989

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through e

6.8
CVE-2026-10723

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA

6.8
CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API,

6.8
CVE-2026-6390

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one

6.8
CVE-2026-65695

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker

6.8
CVE-2026-50044

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an

6.8
CVE-2026-14827

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in

6.8
CVE-2026-65436

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

6.8
CVE-2026-65923

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository

6.8
CVE-2026-50735

pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me

6.8
CVE-2026-13605

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca

6.8
CVE-2026-13307

Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabilit

6.8
CVE-2026-13309

Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabili

6.8
CVE-2026-46678

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when

6.8
CVE-2026-54249

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and

6.8
CVE-2026-17919

Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to

6.8
CVE-2026-14318

The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H

6.8
CVE-2026-15153

The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative

6.8
CVE-2026-18382

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able

6.8
CVE-2026-67347

Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-loc

6.8
CVE-2026-65834

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet

6.8
CVE-2026-14833

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend

6.8
CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor

6.8
CVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization

6.8
CVE-2026-67311

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail

6.8
CVE-2026-14817

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer

6.8
CVE-2026-18654

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v

6.8
CVE-2026-66313

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

6.8
CVE-2026-14872

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e

6.8
CVE-2026-14939

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi

6.8
CVE-2026-16069

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t

6.8
CVE-2026-16293

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po

6.8
CVE-2026-70620

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke

6.8
CVE-2026-55747

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir

6.8
CVE-2026-39924

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess

6.8
CVE-2026-64993

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo

6.8
CVE-2024-6541

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy

6.8
CVE-2026-5336

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren

6.8
CVE-2026-19017

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started