Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 756/1152
6.1
CVE-2026-60685

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver

6.1
CVE-2026-60802

Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-60815

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th

6.1
CVE-2026-60842

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported vers

6.1
CVE-2026-61220

Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configurat

6.1
CVE-2026-62444

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-62487

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-62505

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

6.1
CVE-2026-64828

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac

6.1
CVE-2026-9066

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse

6.1
CVE-2026-65756

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr

6.1
CVE-2026-65899

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPuri

6.1
CVE-2026-65900

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RE

6.1
CVE-2026-65901

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled n

6.1
CVE-2026-65902

DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS an

6.1
CVE-2026-65903

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden t

6.1
CVE-2026-65911

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int

6.1
CVE-2026-65912

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function

6.1
CVE-2026-65913

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass

6.1
CVE-2026-65914

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing cont

6.1
CVE-2026-65697

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that

6.1
CVE-2026-15346

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '

6.1
CVE-2026-56391

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch

6.1
CVE-2026-56392

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation

6.1
CVE-2026-66010

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL

6.1
CVE-2026-8308

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa

6.1
CVE-2026-10082

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it

6.1
CVE-2026-12982

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it

6.1
CVE-2026-13400

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl

6.1
CVE-2026-14190

The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input

6.1
CVE-2026-66390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th

6.1
CVE-2026-64645

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr

6.1
CVE-2026-53666

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allo

6.1
CVE-2026-53669

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backsl

6.1
CVE-2026-51565

Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker

6.1
CVE-2026-17528

Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element.

6.1
CVE-2026-14171

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick

6.1
CVE-2026-8167

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu

6.1
CVE-2026-42494

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.1
CVE-2026-65882

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle w

6.1
CVE-2026-18084

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackB

6.1
CVE-2026-14515

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptin

6.1
CVE-2026-18197

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow

6.1
CVE-2026-65946

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

6.1
CVE-2026-66490

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

6.1
CVE-2026-54663

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol

6.1
CVE-2026-16465

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili

6.1
CVE-2025-65337

Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address

6.1
CVE-2026-17797

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-17818

Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started