Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 73/129
9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization

9.8
CVE-2026-51190

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw

9.8
CVE-2026-51775

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati

9.8
CVE-2026-52102

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe

9.8
CVE-2026-69240

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl

9.8
CVE-2026-18684

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f

9.8
CVE-2026-48333

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca

9.8
CVE-2026-18685

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the

9.8
CVE-2026-18686

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of

9.8
CVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten

9.8
CVE-2026-64564

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-

9.8
CVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS

9.8
CVE-2026-15721

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig

9.8
CVE-2026-61514

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent

9.8
CVE-2026-61515

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo

9.8
CVE-2026-69098

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows

9.8
CVE-2025-29296

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V

9.8
CVE-2026-63455

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated

9.8
CVE-2026-63456

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated

9.8
CVE-2026-24254

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an ou

9.8
CVE-2017-20241

Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can

9.8
CVE-2017-20242

Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker ca

9.8
CVE-2026-0163

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem

9.8
CVE-2026-49435

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote att

9.8
CVE-2026-69703

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ th

9.8
CVE-2026-70552

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthe

9.8
CVE-2026-70553

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP

9.8
CVE-2026-45538

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP mes

9.8
CVE-2026-66902

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy

9.8
CVE-2026-70554

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod

9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac

9.8
CVE-2026-61486

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc

9.8
CVE-2026-64566

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_s

9.8
CVE-2026-71207

The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut

9.8
CVE-2026-71214

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur

9.8
CVE-2026-66747

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across

9.8
CVE-2026-71231

IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod

9.8
CVE-2026-71237

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa

9.8
CVE-2026-71248

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P

9.8
CVE-2026-71254

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F

9.8
CVE-2026-71256

nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden

9.8
CVE-2026-71262

IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (

9.8
CVE-2026-71267

microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name

9.8
CVE-2026-71278

rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont

9.8
CVE-2026-71289

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi

9.8
CVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo

9.8
CVE-2026-20272

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

9.8
CVE-2025-63823

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote

9.8
CVE-2026-52466

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to sto

9.8
CVE-2026-67870

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started