Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 75/454
8.8
CVE-2026-62675

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipar

8.8
CVE-2026-62677

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authe

8.8
CVE-2026-77234

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to exec

8.8
CVE-2026-50538

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or ma

8.8
CVE-2026-62316

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/

8.8
CVE-2026-31936

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object informat

8.8
CVE-2026-33240

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS)

8.8
CVE-2026-53527

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user upda

8.8
CVE-2026-53528

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset re

8.8
CVE-2026-19883

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to

8.8
CVE-2026-76789

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce che

8.8
CVE-2026-59808

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() retur

8.8
CVE-2026-71513

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle m

8.8
CVE-2026-74607

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and mirro

8.8
CVE-2026-74615

In the Linux kernel, the following vulnerability has been resolved: vxlan: do not arm the ageing timer on a device that

8.8
CVE-2026-74629

In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr A di

8.8
CVE-2026-74649

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix missing shared-key auth cha

8.8
CVE-2026-74655

In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: fix TX DMA buffer flush When tr

8.8
CVE-2026-74691

In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stoppi

8.8
CVE-2026-74702

In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpoint

8.8
CVE-2026-0551

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

8.8
CVE-2026-16149

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,

8.8
CVE-2026-78170

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formCo

8.8
CVE-2026-78314

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78315

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78316

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78317

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-59565

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of

8.8
CVE-2026-59567

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an un

8.8
CVE-2026-76841

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 expos

8.8
CVE-2026-76847

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact

8.8
CVE-2026-78376

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory

8.8
CVE-2026-13212

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring

8.8
CVE-2025-36940

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U

8.8
CVE-2026-76073

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label

8.8
CVE-2026-76836

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu

8.8
CVE-2026-32560

Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versio

8.8
CVE-2026-32561

Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

8.8
CVE-2026-56702

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that all

8.8
CVE-2026-75574

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as

8.8
CVE-2026-78685

Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote

8.8
CVE-2026-19892

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to

8.8
CVE-2026-16601

The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited

8.8
CVE-2026-49050

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2

8.8
CVE-2026-19949

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functiona

8.8
CVE-2026-79665

Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireSc

8.8
CVE-2026-57863

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated co

8.8
CVE-2026-79784

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class

8.8
CVE-2026-24170

NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user

8.8
CVE-2026-55585

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, sche

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started