Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 73/91
CVE-2026-71553

ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id acce

CVE-2026-71858

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortc

CVE-2026-35219

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps

CVE-2026-47683

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js

CVE-2026-75529

Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download

CVE-2026-75531

Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted

CVE-2026-11817

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments a

CVE-2026-43971

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via une

CVE-2026-18929

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The

CVE-2026-75838

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hoo

CVE-2026-18751

External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App:

CVE-2026-1199

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly co

CVE-2026-23922

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a mali

CVE-2026-23929

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter proces

CVE-2026-23930

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically cra

CVE-2026-23931

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values

CVE-2026-23933

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed

CVE-2026-23934

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically craft

CVE-2026-23935

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript

CVE-2026-23937

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential

CVE-2026-23938

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/sc

CVE-2026-45532

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnera

CVE-2026-59781

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether th

CVE-2026-17084

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoi

CVE-2026-68939

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read ac

CVE-2026-71539

n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation

CVE-2026-75872

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers

CVE-2026-15806

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HT

CVE-2026-62357

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INIT

CVE-2026-63328

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct pat

CVE-2026-71574

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

CVE-2026-72532

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - A

CVE-2026-73073

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim co

CVE-2026-73337

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks

CVE-2026-73371

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper

CVE-2026-73373

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of

CVE-2026-19869

@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-r

CVE-2026-54730

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust

CVE-2026-57580

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with th

CVE-2026-61634

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-63335

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-63336

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-63337

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-69219

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-69220

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-71572

Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of out

CVE-2026-71573

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementat

CVE-2026-72531

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.

CVE-2026-73336

Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags

CVE-2026-73372

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started