Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 74/91
CVE-2026-50161

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the

CVE-2026-50167

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpo

CVE-2026-53533

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), a

CVE-2026-63641

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as E

CVE-2026-63642

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfee

CVE-2026-63643

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodule

CVE-2026-71878

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated P

CVE-2026-71879

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Tool

CVE-2026-71880

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows

CVE-2026-17106

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers

CVE-2026-52735

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the

CVE-2026-52736

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node

CVE-2026-52738

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of trans

CVE-2026-65984

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in ser

CVE-2026-65985

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-reques

CVE-2026-67440

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVIC

CVE-2026-67443

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard autho

CVE-2026-52817

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1

CVE-2026-53453

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio

CVE-2026-53454

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio

CVE-2026-53455

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio

CVE-2026-53456

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio

CVE-2026-53457

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy statel

CVE-2026-53458

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio

CVE-2026-53759

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve

CVE-2026-15315

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification m

CVE-2026-15316

An improper input validation vulnerability in the configuration service for processing encrypted credential data has bee

CVE-2026-21580

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was intro

CVE-2026-21582

This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduce

CVE-2026-21584

This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.

CVE-2026-52875

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-sc

CVE-2026-62292

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image

CVE-2026-11751

A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification ma

CVE-2026-76164

AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low

CVE-2026-16440

In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.

CVE-2026-18371

HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user inte

CVE-2026-18372

CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arb

CVE-2026-19489

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr

CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr

CVE-2026-67363

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and pa

CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.

CVE-2026-65609

nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields de

CVE-2026-65610

nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influenc

CVE-2026-65611

nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or

CVE-2026-65612

nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, re

CVE-2026-74803

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbi

CVE-2026-74804

Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filte

CVE-2026-75114

Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The refere

CVE-2026-76236

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to

CVE-2026-76237

stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quara

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started