Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 72/436
6.5
CVE-2026-57392

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control

6.5
CVE-2026-57393

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF I

6.5
CVE-2026-57395

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control

6.5
CVE-2026-57400

Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocomm

6.5
CVE-2026-57402

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Re

6.5
CVE-2026-57404

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme

6.5
CVE-2026-57406

Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configure

6.5
CVE-2026-57408

Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting

6.5
CVE-2026-57412

Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured

6.5
CVE-2026-57414

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatB

6.5
CVE-2026-57418

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In

6.5
CVE-2026-57419

Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce all

6.5
CVE-2026-57420

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box W

6.5
CVE-2026-57424

Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting

6.5
CVE-2026-57693

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inser

6.5
CVE-2026-57694

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly

6.5
CVE-2026-57698

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooComm

6.5
CVE-2026-57711

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins Suppor

6.5
CVE-2026-57780

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision En

6.5
CVE-2026-57783

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker

6.5
CVE-2026-57812

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit

6.5
CVE-2026-59523

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit

6.5
CVE-2026-62147

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons

6.5
CVE-2026-58408

ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admi

6.5
CVE-2026-12482

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the

6.5
CVE-2026-49488

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. Th

6.5
CVE-2026-58478

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability

6.5
CVE-2026-11944

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment

6.5
CVE-2026-59198

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer w

6.5
CVE-2026-34348

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over

6.5
CVE-2026-47282

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos

6.5
CVE-2026-49799

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att

6.5
CVE-2026-54108

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing o

6.5
CVE-2026-55003

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-57976

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ

6.5
CVE-2026-57979

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

6.5
CVE-2026-59888

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From

6.5
CVE-2026-50366

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ

6.5
CVE-2026-50376

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50445

Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50468

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-50497

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo

6.5
CVE-2026-50504

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-54116

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in

6.5
CVE-2026-54126

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-55051

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information

6.5
CVE-2026-55054

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started