Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 74/129
9.8
CVE-2026-67873

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ

9.8
CVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level

9.8
CVE-2026-64597

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay

9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit

9.8
CVE-2026-68079

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of

9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info

9.8
CVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

9.8
CVE-2026-53975

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu

9.8
CVE-2026-65507

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

9.8
CVE-2026-65552

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

9.8
CVE-2026-65556

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

9.8
CVE-2026-65571

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

9.8
CVE-2026-65572

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

9.8
CVE-2026-65573

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

9.8
CVE-2026-65574

Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

9.8
CVE-2026-65575

Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

9.8
CVE-2026-65576

Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

9.8
CVE-2026-65577

Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

9.8
CVE-2026-65578

Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

9.8
CVE-2026-65579

Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

9.8
CVE-2026-65581

Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

9.8
CVE-2026-66662

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

9.8
CVE-2026-67261

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injecti

9.8
CVE-2026-15732

A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona

9.8
CVE-2026-15733

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio

9.8
CVE-2026-15734

A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att

9.8
CVE-2026-17032

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo

9.8
CVE-2026-48085

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

9.8
CVE-2026-48087

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS

9.8
CVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module.

9.8
CVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or

9.8
CVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path)

9.8
CVE-2026-62873

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat

9.8
CVE-2026-14364

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp

9.8
CVE-2026-14365

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in

9.8
CVE-2026-14205

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid

9.8
CVE-2026-16258

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u

9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from

9.8
CVE-2022-4995

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent

9.8
CVE-2026-19264

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat

9.8
CVE-2026-61808

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds t

9.8
CVE-2026-14526

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

9.8
CVE-2026-68082

In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lock

9.8
CVE-2026-71944

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71945

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71946

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71947

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71948

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started