Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 77/436
6.5
CVE-2026-2406

Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr

6.5
CVE-2025-13146

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a

6.5
CVE-2026-16544

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are

6.5
CVE-2026-65589

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writin

6.5
CVE-2026-65594

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was

6.5
CVE-2026-65599

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Goo

6.5
CVE-2026-13192

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PD

6.5
CVE-2026-14932

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vuln

6.5
CVE-2026-50248

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that res

6.5
CVE-2026-10822

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ

6.5
CVE-2026-13055

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)

6.5
CVE-2026-13056

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object

6.5
CVE-2026-13058

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf

6.5
CVE-2026-13060

An authenticated user with limited read privileges may be able to access documents from collections they are not authori

6.5
CVE-2026-13062

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal

6.5
CVE-2026-13064

Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in

6.5
CVE-2026-13065

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator

6.5
CVE-2026-13066

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i

6.5
CVE-2026-13069

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c

6.5
CVE-2026-13071

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express

6.5
CVE-2026-13075

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th

6.5
CVE-2026-13076

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p

6.5
CVE-2026-9737

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m

6.5
CVE-2026-64794

Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions -

6.5
CVE-2026-13009

The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param

6.5
CVE-2026-13119

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan

6.5
CVE-2026-15448

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order

6.5
CVE-2026-15761

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event

6.5
CVE-2026-15906

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th

6.5
CVE-2026-16078

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all

6.5
CVE-2026-64872

Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es

6.5
CVE-2026-64875

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forw

6.5
CVE-2026-65713

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera

6.5
CVE-2026-27372

Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

6.5
CVE-2026-27403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub L

6.5
CVE-2026-57373

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

6.5
CVE-2026-57384

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

6.5
CVE-2026-57425

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

6.5
CVE-2026-57717

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

6.5
CVE-2026-57808

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

6.5
CVE-2026-59513

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

6.5
CVE-2026-59522

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

6.5
CVE-2026-59524

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

6.5
CVE-2026-61945

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro

6.5
CVE-2026-61946

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

6.5
CVE-2026-65449

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

6.5
CVE-2026-65465

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

6.5
CVE-2026-65470

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

6.5
CVE-2026-65473

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.

6.5
CVE-2026-65475

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Im

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started