Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 77/454
8.8
CVE-2026-19042

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote

8.8
CVE-2026-80348

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods i

8.8
CVE-2026-63041

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack

8.8
CVE-2026-80547

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Implement a crw lock Unlike the cha

8.8
CVE-2026-80548

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Selectively expand io_mutex The io_

8.8
CVE-2026-80552

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions

8.8
CVE-2026-80553

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The init

8.8
CVE-2026-80576

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring pack

8.8
CVE-2025-56798

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows

8.8
CVE-2026-58474

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote atta

8.8
CVE-2026-68861

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS

8.8
CVE-2026-74770

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS

8.8
CVE-2026-77018

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate

8.8
CVE-2026-78333

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticat

8.8
CVE-2026-78257

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

8.8
CVE-2026-81271

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

8.8
CVE-2026-81579

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64

8.8
CVE-2026-81581

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attac

8.8
CVE-2026-81625

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected p

8.8
CVE-2026-10036

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary c

8.8
CVE-2026-54721

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1

8.8
CVE-2026-76639

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows networ

8.8
CVE-2026-18965

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on th

8.8
CVE-2026-39944

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

8.8
CVE-2026-75339

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload

8.8
CVE-2026-75419

go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/s

8.8
CVE-2026-75814

The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management inte

8.8
CVE-2026-76060

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HT

8.8
CVE-2026-78037

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated atta

8.8
CVE-2026-82072

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins

8.8
CVE-2026-80601

In the Linux kernel, the following vulnerability has been resolved: batman-adv: gw: acquire ethernet header only after

8.8
CVE-2026-80604

In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for numbe

8.8
CVE-2026-80608

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix iommu domain lifetime race durin

8.8
CVE-2026-80633

In the Linux kernel, the following vulnerability has been resolved: iommufd: Take dma_resv lock before dma_buf_unpin()

8.8
CVE-2026-80635

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from short trigger BA f

8.8
CVE-2026-80638

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove_refc

8.8
CVE-2026-80672

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix u16 truncation of restart-area length che

8.8
CVE-2026-80683

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: give the socket its own sco_conn re

8.8
CVE-2026-80692

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/l

8.8
CVE-2026-80721

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references

8.8
CVE-2026-80722

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params befo

8.8
CVE-2026-80724

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becom

8.8
CVE-2026-55485

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,

8.8
CVE-2026-55521

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPac

8.8
CVE-2026-72984

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

8.8
CVE-2026-81849

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before

8.8
CVE-2026-82278

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authen

8.8
CVE-2026-18729

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to impro

8.8
CVE-2026-81532

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-

8.8
CVE-2026-82447

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first throu

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started