Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 773/1152
5.9
CVE-2026-62899

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker

5.9
CVE-2026-62900

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose

5.9
CVE-2026-68819

Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

5.9
CVE-2026-12233

The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre

5.9
CVE-2026-18663

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess

5.9
CVE-2026-69107

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

5.9
CVE-2026-19642

An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authentica

5.9
CVE-2026-73344

Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

5.9
CVE-2026-53801

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows

5.9
CVE-2026-57886

Cross-repository issue/comment attachment re-linking can expose private attachment content

5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti

5.9
CVE-2026-56860

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer

5.9
CVE-2026-16739

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request

5.9
CVE-2026-74244

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker

5.9
CVE-2026-74245

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could downloa

5.9
CVE-2026-13700

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request a

5.9
CVE-2026-68762

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

5.9
CVE-2026-45791

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/

5.9
CVE-2026-65329

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.

5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string

5.9
CVE-2026-50139

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit

5.9
CVE-2026-52739

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placi

5.9
CVE-2026-70677

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

5.9
CVE-2026-70716

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

5.9
CVE-2026-70789

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

5.9
CVE-2026-71075

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

5.9
CVE-2026-73909

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

5.9
CVE-2026-27365

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Publi

5.9
CVE-2026-49870

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at

5.9
CVE-2026-16827

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use

5.9
CVE-2026-76320

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authentic

5.9
CVE-2026-76393

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe

5.9
CVE-2026-76400

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

5.9
CVE-2026-76401

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

5.9
CVE-2026-76956

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w

5.9
CVE-2026-66595

Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

5.9
CVE-2025-62300

HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can

5.9
CVE-2026-55558

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib

5.9
CVE-2026-75514

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and ant

5.9
CVE-2026-77587

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg rev

5.9
CVE-2026-49244

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP

5.9
CVE-2026-59296

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a danger

5.9
CVE-2026-76876

Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sens

5.9
CVE-2026-53572

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constru

5.9
CVE-2026-69224

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff

5.9
CVE-2026-69225

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that m

5.9
CVE-2026-62385

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all

5.9
CVE-2026-59295

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) cond

5.9
CVE-2026-79652

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat

5.9
CVE-2026-63074

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a C

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started