Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 759/1152
6.1
CVE-2026-16732

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the for

6.1
CVE-2026-62499

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security).

6.1
CVE-2026-62568

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

6.1
CVE-2026-70765

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

6.1
CVE-2026-70768

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

6.1
CVE-2026-70838

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.1
CVE-2026-70923

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.1
CVE-2026-70961

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

6.1
CVE-2026-71004

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71005

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71006

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71011

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71019

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71025

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71031

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.1
CVE-2026-71125

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

6.1
CVE-2026-71154

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.1
CVE-2026-73869

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.1
CVE-2026-73870

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.1
CVE-2026-73898

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.1
CVE-2026-66358

A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.

6.1
CVE-2026-75900

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the

6.1
CVE-2026-75148

cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_valid

6.1
CVE-2026-40507

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handl

6.1
CVE-2026-20302

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to

6.1
CVE-2026-55087

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path

6.1
CVE-2026-67189

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffi

6.1
CVE-2026-71368

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected

6.1
CVE-2026-54770

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob

6.1
CVE-2026-69234

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allo

6.1
CVE-2026-69235

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,

6.1
CVE-2026-69236

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote,

6.1
CVE-2026-68767

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an inpu

6.1
CVE-2026-68768

hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. Wh

6.1
CVE-2026-5389

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializ

6.1
CVE-2026-5751

justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability

6.1
CVE-2026-6827

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling.

6.1
CVE-2026-74793

justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler

6.1
CVE-2026-77088

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code s

6.1
CVE-2026-8630

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the seriali

6.1
CVE-2026-19852

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers

6.1
CVE-2026-65053

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without esca

6.1
CVE-2026-78475

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin al

6.1
CVE-2026-71503

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration templa

6.1
CVE-2022-30983

A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows rem

6.1
CVE-2026-55059

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.1
CVE-2026-56704

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without

6.1
CVE-2026-17089

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S

6.1
CVE-2026-75038

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This is

6.1
CVE-2026-55530

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval d

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started