Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 758/1152
6.1
CVE-2025-15678

The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use

6.1
CVE-2026-11588

The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route

6.1
CVE-2026-66370

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow

6.1
CVE-2026-66829

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow

6.1
CVE-2026-66843

Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex

6.1
CVE-2026-68747

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the

6.1
CVE-2026-71435

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automag

6.1
CVE-2026-71478

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes

6.1
CVE-2026-14331

The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a

6.1
CVE-2026-15032

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an

6.1
CVE-2026-16535

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r

6.1
CVE-2026-16032

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an

6.1
CVE-2026-17019

The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and

6.1
CVE-2026-21063

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers t

6.1
CVE-2026-21073

Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary

6.1
CVE-2026-72574

A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control

6.1
CVE-2026-72587

A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison

6.1
CVE-2026-69116

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives.

6.1
CVE-2026-66771

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio

6.1
CVE-2026-72925

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi

6.1
CVE-2026-73084

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi

6.1
CVE-2026-66146

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions

6.1
CVE-2026-73235

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru

6.1
CVE-2026-12232

The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal

6.1
CVE-2026-17013

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it

6.1
CVE-2026-64955

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CS

6.1
CVE-2026-48550

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via

6.1
CVE-2026-73237

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1.

6.1
CVE-2026-73238

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme

6.1
CVE-2026-19657

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker wh

6.1
CVE-2026-73434

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available g

6.1
CVE-2026-17431

PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and

6.1
CVE-2026-73628

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-UR

6.1
CVE-2026-73506

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune

6.1
CVE-2026-73572

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla

6.1
CVE-2026-73671

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in clas

6.1
CVE-2026-73037

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter

6.1
CVE-2026-73038

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to esca

6.1
CVE-2026-73531

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers

6.1
CVE-2026-56858

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitr

6.1
CVE-2026-15009

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vu

6.1
CVE-2026-19712

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in

6.1
CVE-2026-74796

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attack

6.1
CVE-2026-50771

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary co

6.1
CVE-2026-63670

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed e

6.1
CVE-2026-67925

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpo

6.1
CVE-2026-68765

hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 mod

6.1
CVE-2026-30250

Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90

6.1
CVE-2026-52606

A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitr

6.1
CVE-2026-52609

A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitr

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started