Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 73/454
8.8
CVE-2026-71045

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

8.8
CVE-2026-71046

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

8.8
CVE-2026-71051

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

8.8
CVE-2026-71052

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Se

8.8
CVE-2026-71055

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se

8.8
CVE-2026-71058

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions t

8.8
CVE-2026-71067

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

8.8
CVE-2026-71106

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component:

8.8
CVE-2026-71150

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-76034

Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code ou

8.8
CVE-2026-76038

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside

8.8
CVE-2026-76040

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social

8.8
CVE-2026-76043

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code

8.8
CVE-2026-76045

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code ins

8.8
CVE-2026-76047

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside

8.8
CVE-2026-50186

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project

8.8
CVE-2026-50191

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account tak

8.8
CVE-2026-52872

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSu

8.8
CVE-2026-52876

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the op

8.8
CVE-2026-66602

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Reque

8.8
CVE-2026-49415

During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated

8.8
CVE-2026-49418

When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range

8.8
CVE-2026-49419

When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's curr

8.8
CVE-2026-70408

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has adm

8.8
CVE-2026-14334

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG

8.8
CVE-2026-16617

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before o

8.8
CVE-2026-19842

The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing t

8.8
CVE-2026-49420

The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewr

8.8
CVE-2026-49427

Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an obje

8.8
CVE-2024-58376

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli

8.8
CVE-2026-54795

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

8.8
CVE-2026-71694

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619

8.8
CVE-2026-75918

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled.

8.8
CVE-2026-76220

GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypasse

8.8
CVE-2026-76221

GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attacker

8.8
CVE-2026-76224

ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Grem

8.8
CVE-2026-16814

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buff

8.8
CVE-2026-44829

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/c

8.8
CVE-2026-49255

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm con

8.8
CVE-2026-58565

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged atta

8.8
CVE-2026-71176

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

8.8
CVE-2026-71961

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated

8.8
CVE-2026-62666

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6,

8.8
CVE-2026-61518

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to de

8.8
CVE-2026-75149

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attacker

8.8
CVE-2026-16841

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

8.8
CVE-2026-16842

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

8.8
CVE-2026-16844

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

8.8
CVE-2026-16847

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buff

8.8
CVE-2026-16848

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started