Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 72/129
9.8
CVE-2025-69947

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

9.8
CVE-2026-35847

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the Chec

9.8
CVE-2026-68502

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.

9.8
CVE-2026-68503

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships def

9.8
CVE-2026-38709

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2

9.8
CVE-2026-14537

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0

9.8
CVE-2026-43830

Full details and mitigation steps are currently restricted and will be published at a later date.

9.8
CVE-2026-63223

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i

9.8
CVE-2026-14483

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver

9.8
CVE-2026-14919

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be

9.8
CVE-2026-17561

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons

9.8
CVE-2026-16504

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw

9.8
CVE-2026-67822

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu

9.8
CVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic

9.8
CVE-2026-38711

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2

9.8
CVE-2025-69946

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr

9.8
CVE-2025-69948

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

9.8
CVE-2026-38708

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2

9.8
CVE-2026-38713

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2

9.8
CVE-2026-51785

An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted req

9.8
CVE-2026-68770

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code e

9.8
CVE-2026-52134

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au

9.8
CVE-2026-68771

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic

9.8
CVE-2026-15964

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese

9.8
CVE-2026-66402

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in

9.8
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll

9.8
CVE-2026-67324

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>

9.8
CVE-2026-67341

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with

9.8
CVE-2026-67342

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, P

9.8
CVE-2026-8457

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc

9.8
CVE-2026-16256

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av

9.8
CVE-2026-65321

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar

9.8
CVE-2026-12872

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload

9.8
CVE-2026-16060

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the conten

9.8
CVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an un

9.8
CVE-2026-16300

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticate

9.8
CVE-2026-18588

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi

9.8
CVE-2026-18589

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file na

9.8
CVE-2026-2346

Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ

9.8
CVE-2026-18108

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr

9.8
CVE-2026-18601

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi

9.8
CVE-2026-64827

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp

9.8
CVE-2026-18602

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_conf

9.8
CVE-2026-41452

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated

9.8
CVE-2026-18612

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p

9.8
CVE-2026-18613

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of t

9.8
CVE-2026-18614

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file

9.8
CVE-2026-18615

A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate

9.8
CVE-2026-18616

A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of

9.8
CVE-2026-38447

osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started